Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-24956

Web Sudo should be able to be subverted for non browsers (eg scripts) via a HTTP header

XMLWordPrintable

      We do this for XSRF protection. Basically you should be able to subvert the web sudo mechanism via a HTTP header.

      This posts shows the use case

      https://answers.atlassian.com/questions/1273/jira-jelly-runner-via-cron-in-v4-3-4

      I believe it just as secure since web sudo is really design to stop some one using your browser (directly or via XSRF) to perform admin actions as you.

      Scripts don't suffer this problem. The need your username and password to run at all.

              rsmart metapoint
              bbaker ɹǝʞɐq pɐɹq
              Votes:
              4 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: