-
Bug
-
Resolution: Fixed
-
Low (View bug fix roadmap)
-
7.12.2
-
7.12
-
Severity 2 - Major
-
-
Problem
Support for using os_username and os_password to authenticate when used as url query parameters has been deprecated in Jira 8.0.0.
It is possible to disable support for os_username & os_password as url query parameters for authentication by setting allowUrlParameterValue to false in <JIRA_install>/atlassian-jira/WEB-INF/web.xml .
example:
<filter> <filter-name>login</filter-name> <filter-class>com.atlassian.jira.web.filters.JiraLoginFilter</filter-class> <init-param> <param-name>allowUrlParameterValue</param-name> <param-value>false</param-value> </init-param> </filter>
- relates to
-
JRASERVER-38548 Remove url parameter support for os_username, os_password
-
- Closed
-
(4 mentioned in)
[JRASERVER-67979] Deprecate support for authenticating using os_username, os_password as url query parameters
Remote Link | New: This issue links to "Page (Confluence)" [ 840380 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 788100 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 726307 ] |
Remote Link | Original: This issue links to "Page (Atlassian Documentation)" [ 527233 ] |
Remote Link | New: This issue links to "Page (Atlassian Documentation)" [ 527233 ] |
Remote Link | New: This issue links to "Page (Atlassian Documentation)" [ 516451 ] |
Remote Link | New: This issue links to "Page (Atlassian Documentation)" [ 515961 ] |
Remote Link | New: This issue links to "Page (Atlassian Documentation)" [ 515960 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 468765 ] |
Labels | Original: advisory-released exclude-from-security-metrics-page improper-authentication improper-authorization security triaged | New: advisory-released basm exclude-from-security-metrics-page improper-authentication improper-authorization security triaged |