-
Bug
-
Resolution: Fixed
-
Medium (View bug fix roadmap)
-
4.2
-
4.02
-
From the customer support case
When using os_authType=basic to login to JIRA 4.2 a user is able to upload an attachment as a temporary file, but is unable to attach the temporary file to the issue. We noticed the exact same behavior [...] had worked with JIRA 4.1.2.
The Atlassian support people have confirmed this as a bug in 4.2. I suspect at this stage its perhaps related to SER-154.
To re-create :
- Restart your browser each time (basic auth creds are cached by the browser
- Goto jira with ?os_authType=basic to cause a basic auth challenge
- Click Create Issue
- Attach a file
- See the error "Temporary attachment with id '8,995,549,407,744,639,063' not found. Session may have timed out before submitting the form."
It appears the "Attach Files" on view issue is also broken. I managed to get one to work and then a second to fail. I am still investigating this aspect.
- is caused by
-
SER-160 Session fixation prevention has broken things when basic auth is used in Seraph
-
- RESOLVED
-
[JRASERVER-23188] Basic auth authentication does not allow files to be attached in 4.2
Minimum Version | New: 4.02 |
Workflow | Original: JAC Bug Workflow v2 [ 2835539 ] | New: JAC Bug Workflow v3 [ 2925273 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v7 - Restricted [ 2562037 ] | New: JAC Bug Workflow v2 [ 2835539 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v6 - Restricted [ 1527712 ] | New: JIRA Bug Workflow w Kanban v7 - Restricted [ 2562037 ] |
Labels | Original: security | New: affects-server security |
Component/s | Original: Security [Deprecated] [ 11831 ] | |
Labels | New: security |
Workflow | Original: JIRA Bug Workflow w Kanban v6 [ 671204 ] | New: JIRA Bug Workflow w Kanban v6 - Restricted [ 1527712 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v5 [ 657560 ] | New: JIRA Bug Workflow w Kanban v6 [ 671204 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v5 [ 270764 ] | New: JIRA Bug Workflow w Kanban v6 [ 657560 ] |
Hi,
i see the same on Jira 6.2.2.Is this related to the session timeout