-
Bug
-
Resolution: Fixed
-
High
-
4
-
Severity 3 - Minor
-
1
-
Summary
In the notification sent to the users generate their first password, the button Set my password does not work since it contains the os_username url parameter that has been blocked as documented in the JIRA and Confluence Cloud os_username and os_password embedded in URL no longer available KB article.
Indeeed, when clicking on the "Set my Password" button the users are sent to a link like the below one:
Environment
JIRA Cloud 1000.747.0
Steps to Reproduce
- Invite a new user to the instance, e.g. by using the REST API endpoint /rest/api/latest/user (sending the parameter "notification":"true").
- The user that got invited opens the "Account created" notification and click on the Set my password button
Expected Results
The link open correctly and the user is able to set the password
Actual Results
The below message is returned:
REQUEST DENIED. Refer to https://confluence.atlassian.com/display/CLOUDKB/JIRA+and+Confluence+Cloud+os_username+and+os_password+embedded+in+URL+no+longer+available for details.
Workaround
Depending if your instance is using Atlassian Accounts or not, you can either:
- Use the password reset link that is present at the bottom of the notification.
- Reset the password from https://NAME.atlassian.net/login/forgot
- is caused by
-
SER-199 Make support for os_username and os_password as url parameters require opting in
-
- RESOLVED
-
-
JRASERVER-38548 Remove url parameter support for os_username, os_password
-
- Closed
-
-
SER-194 Remove support for os_username, os_password and os_cookie
-
- Open
-
-
HPT-7495 Failed to load
-
HOT-58607 You do not have permission to view this issue
-
JDEV-37877 Loading...
-
SDENG-958 Loading...
- relates to
-
HOT-61814 Loading...
Form Name |
---|
[JRACLOUD-65287] The the os_username parameter has been blocked but it is still used in the users onboarding notifications
Remote Link | New: This issue links to "Page (Confluence)" [ 726208 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v6 - Restricted [ 1645175 ] | New: JAC Bug Workflow v3 [ 3362163 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 437712 ] |
Remote Link | Original: This issue links to "Page (Extranet)" [ 259386 ] |
Component/s | New: Events & Notifications - Email [ 46553 ] | |
Component/s | Original: Events & Notifications - Email [ 10471 ] | |
Key |
Original:
|
New:
|
Affects Version/s | New: 1000.747.0 [ 69750 ] | |
Affects Version/s | Original: 1000.747.0 [ 66447 ] | |
Project | Original: JIRA (including JIRA Core) [ 10240 ] | New: JIRA for Cloud [ 18514 ] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: In Progress [ 3 ] | New: Resolved [ 5 ] |
UIS - Server | New: 1 |
Support reference count | Original: 2 | New: 4 |
Fixed by changing the redirect rules to only look for os_password