• 1
    • We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

      Suggestion

      The current implementation of Jira Service Management requires unauthenticated outbound REST API call from the App to Jira.

      These calls are /server-info and /rest/nativemobile/1.1/info/login and are described in https://confluence.atlassian.com/jirakb/can-t-check-compatibility-error-in-the-jira-server-mobile-app-954244691.html

      Some customers may have a WAF, proxy, or other appliance in between the client App and Jira that block unauthenticated access to these calls

      Solutions include:

      However, some customers may not be able to use either option, since MDM is not used, or the third party service cannot be configured (either for business, or technical reason) to exclude the required URLS.

      This results in inability to use the Jira Mobile App.

      Suggest solution

      Redesign the pre-login phase of JMA to not require unauthenticated call

            [JRASERVER-72327] Skip unauthenticated API requirement for Jira Mobile App

            gr_maxim added a comment - - edited

            We (@Symantec/Broadcom) are also would like this issue to be resolved. Other solutions are not suitable for us. 

            If you have any other suggestions, we would like to hear about them.

            I would like to suggest a quick-win that might work for some cases: A deep-link with query parameters for the base-url and skipInfo flag. but this solution probably requires a security-risk review.

            gr_maxim added a comment - - edited We (@Symantec/Broadcom) are also would like this issue to be resolved. Other solutions are not suitable for us.  If you have any other suggestions, we would like to hear about them. I would like to suggest a quick-win that might work for some cases: A deep-link with query parameters for the base-url and skipInfo flag. but this solution probably requires a security-risk review.

              Unassigned Unassigned
              allewellyn@atlassian.com Alex [Atlassian,PSE]
              Votes:
              2 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: