Uploaded image for project: 'Identity'
  1. Identity
  2. ID-61

Password reset link requires user login crowd REST end user authentication

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Medium Medium
    • None

      When going to https://rokkmedia.atlassian.net/login? and clicking one the Unable to access your account? link and going to https://rokkmedia.atlassian.net/login/forgot you can get the password reset link email but when you click on the button it will redirect you to the reset password page but the authentication pop-up comes up. If you cancel / exit it will redirect you to https://rokkmedia.atlassian.net/login where you can't cahnge the password.

            [ID-61] Password reset link requires user login crowd REST end user authentication

            Fix confirmed, thank you.

            Stephen Dharma added a comment - Fix confirmed, thank you.

            David Cook added a comment -

            Thanks for getting back to me Justin. I just tried again and did not see the bug.

            Damn you Shaun and the product growth team!! I shake my fist at you!

            David Cook added a comment - Thanks for getting back to me Justin. I just tried again and did not see the bug. Damn you Shaun and the product growth team!! I shake my fist at you!

            Could I ask if anyone is seeing this, could they capture the network calls in the developer toolbar of the browser you are using, so we can see which network call is prompting for the authentication call to be made?

            This is not happening on our production test instances, so at the moment I am guessing it might be a growth experiment being run in OnDemand that is hitting a protected resource.

            Justin Koke [Administrative Account] added a comment - Could I ask if anyone is seeing this, could they capture the network calls in the developer toolbar of the browser you are using, so we can see which network call is prompting for the authentication call to be made? This is not happening on our production test instances, so at the moment I am guessing it might be a growth experiment being run in OnDemand that is hitting a protected resource.

            This is happening to me too. A hard refresh does not fix the issue and neither does restarting my browser. This is completely preventing me from accessing Atlassian OnDemand.

            David Cook added a comment - This is happening to me too. A hard refresh does not fix the issue and neither does restarting my browser. This is completely preventing me from accessing Atlassian OnDemand.

            Justin Koke added a comment - - edited

            dnicholson The answer is yes ... everyones machines are in the same boat ... As hhung asked, did the hard refresh fix the problem?

            Justin Koke added a comment - - edited dnicholson The answer is yes ... everyones machines are in the same boat ... As hhung asked, did the hard refresh fix the problem?

            Helen Hung (Inactive) added a comment - - edited

            dnicholson are you saying that even having done a hard refresh, it doesn't resolve itself on your machine?

            Helen Hung (Inactive) added a comment - - edited dnicholson are you saying that even having done a hard refresh, it doesn't resolve itself on your machine?

            Stephen Dharma added a comment - - edited

            Getting the same problem.

            JST-101691
            When the JIRA Administrator had created a "JIRA User" using option "Email a link to the user to set their password", an e-mail was sent to the User. But after clicking the "Set my password" link provided, an authentication window appeared, displaying "Authentication Required. The Server https://asyst-jira.atlassian.net:443 requires a username and password. The server says: Crowd REST End User Authentication".

            This authentication window causes Users being unable to Set their Password and preventing new users to login into JIRA.

            Steps to reproduce issue:
            1. JIRA Administrator create a new "JIRA User", using option "Email a link to the user to set their password".
            2. JIRA send an e-mail to new "JIRA User".
            3. New "JIRA User" click the "Set my password" button/link provided in the e-mail.
            4. "JIRA User" redirected to "Reset Password" page (browser).
            5. The page display a basic authentication window "Authentication Required. The Server https://<server-name>.atlassian.net:443 requires a username and password. The server says: Crowd REST End User Authentication"; preventing "JIRA User" to set the password.

            Actual result:
            "Set my password" functionality cannot be used.

            Expected result:
            "Set my password" functionality can be used.

            Stephen Dharma added a comment - - edited Getting the same problem. JST-101691 When the JIRA Administrator had created a "JIRA User" using option "Email a link to the user to set their password", an e-mail was sent to the User. But after clicking the "Set my password" link provided, an authentication window appeared, displaying "Authentication Required. The Server https://asyst-jira.atlassian.net:443 requires a username and password. The server says: Crowd REST End User Authentication" . This authentication window causes Users being unable to Set their Password and preventing new users to login into JIRA. Steps to reproduce issue: 1. JIRA Administrator create a new "JIRA User", using option "Email a link to the user to set their password" . 2. JIRA send an e-mail to new "JIRA User". 3. New "JIRA User" click the "Set my password" button/link provided in the e-mail. 4. "JIRA User" redirected to "Reset Password" page (browser). 5. The page display a basic authentication window "Authentication Required. The Server https://<server-name>.atlassian.net:443 requires a username and password. The server says: Crowd REST End User Authentication" ; preventing "JIRA User" to set the password. Actual result: "Set my password" functionality cannot be used. Expected result: "Set my password" functionality can be used.

            jkoke.adm, would this be the case even though we are able to replicate the issue on our machines?

            David Nicholson (Inactive) added a comment - jkoke.adm , would this be the case even though we are able to replicate the issue on our machines?

            This is a client side caching issue .... we will be looking at resolving it in a subsequent release ... a hard reset Shift + refresh should solve the problem.

            Justin Koke added a comment - This is a client side caching issue .... we will be looking at resolving it in a subsequent release ... a hard reset Shift + refresh should solve the problem.

              Unassigned Unassigned
              jrobison1 JordanA
              Affected customers:
              3 This affects my team
              Watchers:
              13 Start watching this issue

                Created:
                Updated:
                Resolved: