Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-24956

Web Sudo should be able to be subverted for non browsers (eg scripts) via a HTTP header

    XMLWordPrintable

Details

    Description

      We do this for XSRF protection. Basically you should be able to subvert the web sudo mechanism via a HTTP header.

      This posts shows the use case

      https://answers.atlassian.com/questions/1273/jira-jelly-runner-via-cron-in-v4-3-4

      I believe it just as secure since web sudo is really design to stop some one using your browser (directly or via XSRF) to perform admin actions as you.

      Scripts don't suffer this problem. The need your username and password to run at all.

      Attachments

        Activity

          People

            rsmart metapoint
            bbaker ɹǝʞɐq pɐɹq
            Votes:
            4 Vote for this issue
            Watchers:
            8 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: