HTTP Basic auth should be enabled by default

XMLWordPrintable

    • Type: Suggestion
    • Resolution: Fixed
    • 4.0
    • Component/s: None

      In JIRA, you need to append &os_authType=basic to the URL to get it to accept standard HTTP Basic auth. Hardly anyone knows about this, and people fall back to using &os_username=..&os_password=.. params, which is even less secure.

      JIRA should accept HTTP Basic auth by default, without any magic parameters.

            Assignee:
            Unassigned
            Reporter:
            Jeff Turner
            Votes:
            1 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: