Uploaded image for project: 'Jira Software Data Center'
  1. Jira Software Data Center
  2. JSWSERVER-20414

Jira's DVCS GitHub connector uses the "access_token" query parameter which is a deprecated authentication method for the GitHub API

      Issue Summary

      Jira's DVCS GitHub connector uses the "access_token" query parameter which is now a deprecated authentication method for the GitHub API

      Steps to Reproduce

      1. Go to Jira Administration > Application > DVCS Accounts
      2. Click on "Link Bitbucket Cloud and GitHub accounts" button
      3. Provide details for GitHub (check screen shot) and proceed.
      4. Make sure that Jira syncs this GitHub data at least once

      Expected Results

      The integration works without any problems.

      Actual Results

      GitHub is currently emailing administrators to inform them that they have an integration that is using this deprecated authentication method. The message looks like this:

      Hi,

      On February 4th, 2020 at 14:01 (UTC) your application (JIRA DVCS) used an access token (with the User-Agent Java/1.8.0_151) as part of a query parameter to access an endpoint through the GitHub API:

      https://api.github.com/repositories/229755391/hooks

      Please use the Authorization HTTP header instead as using the `access_token` query parameter is deprecated.

      Depending on your API usage, we'll be sending you this email reminder once every 3 days for each token and User-Agent used in API calls made on your behalf.
      Just one URL that was accessed with a token and User-Agent combination will be listed in the email reminder, not all.

      Visit https://developer.github.com/changes/2019-11-05-deprecated-passwords-and-authorizations-api/#authenticating-using-query-parameters for more information.

      Thanks,
      The GitHub Team

      Notes

      Workaround

      None

          Form Name

            [JSWSERVER-20414] Jira's DVCS GitHub connector uses the "access_token" query parameter which is a deprecated authentication method for the GitHub API

            Chris Terry made changes -
            Affects Version/s New: 8.5.1 [ 89601 ]
            Christina Jenks made changes -
            Comment [ Will this be fixed in 8.8.0?

            Thanks,

            Tina ]
            Raf made changes -
            Remote Link Original: This issue links to "Page (Confluence)" [ 476040 ]
            Raf made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 509095 ]
            Dario B made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 508185 ]
            Andriy Yakovlev [Atlassian] made changes -
            Fix Version/s New: 8.11.1 [ 92300 ]
            Fix Version/s Original: 8.8.2 [ 91903 ]
            Przemyslaw Czuj made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Waiting for Release [ 12075 ] New: Closed [ 6 ]
            SET Analytics Bot made changes -
            UIS Original: 422 New: 410
            SET Analytics Bot made changes -
            UIS Original: 403 New: 422
            SET Analytics Bot made changes -
            UIS Original: 404 New: 403

              aermolenko Tony Miller
              vpandey2@atlassian.com Vikas Pandey (Inactive)
              Affected customers:
              130 This affects my team
              Watchers:
              166 Start watching this issue

                Created:
                Updated:
                Resolved: