-
Suggestion
-
Resolution: Unresolved
-
None
-
None
-
1
-
Problem Definition
With SSO for Atlassian Server and Data Center App the administrator have the ability to configure customer login through SSO and completely disable the authentication form.
When the authentication form is disabled for both agents and customers, some reset password features are still reachable and could cause confusion to customers.
Suggested Solution
When the authentication form is disabled for both agents and customers, completely disable any page related to the reset password feature.
Workaround
Jira administrators may choose to completely block access to the following URLs:
- /servicedesk/customer/user/forgotpassword
- /servicedesk/customer/user/resetpassword
This can be configured in the Load Balancer, reverse proxy or directly in the Tomcat configuration.
- is related to
-
JSDSERVER-1495 Ability to remove "Forgotten your password" or Contact Administrator type links from logon screen
- Gathering Interest