Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-5433

Logging out from the linked application to Crowd will trigger XSRF error in logs with display of session information.

    XMLWordPrintable

Details

    Description

      Issue Summary

      Logging out from the linked application (Confluence, Jira, Bitbucket etc.) to Crowd will trigger XSRF error in logs with a display of session information.

      Environment

      Crowd 3.4.5
      Confluence 6.15.4
      Use Crowd SSO as user directory in Confluence.

      Steps to Reproduce

      1. Enable SSO from Crowd on Confluence, with linked user directory.
      2. Login to Confluence.
      3. Logout from Confluence

      Expected Results

      Nothing will be logged in Crowd logs when you log in or logout.

      Actual Results

      The crowd will Log XSRF warning and it will display session information.

      The below exception is thrown in the atlassian-crowd.log file:

      2019-07-25 16:11:59,525 http-nio-6345-exec-8 WARN [common.security.jersey.XsrfResourceFilter] XSRF failure not being enforced for request: http://localhost:6345/crowd/rest/usermanagement/1/session/4560Zf6Bdtr5J... , origin: null , referrer: null, method: DELETE
      

      Workaround

      Currently, there is no known workaround for this behavior. A workaround will be added here when available

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              gpaunovic g
              Votes:
              27 Vote for this issue
              Watchers:
              32 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: