Uploaded image for project: 'Jira Software Data Center'
  1. Jira Software Data Center
  2. JSWSERVER-21473

Rate limiting does not work for Cookie based authorization

XMLWordPrintable

    • Icon: Suggestion Suggestion
    • Resolution: Unresolved
    • None
    • Security
    • None
    • 1
    • We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

      Issue Summary

      Rate limiting does not work for Cookie based authorization

       

      This is reproducible on Data Center: Yes

      Steps to Reproduce

      1. Enable rate limiting
      2. Enable Cookie based authorization
      3. We will observe that Jira is not blocking the request if it breaches the limit 

      Expected Results

      We can see the calls are getting blocked when it uses the basic authentication but if the code is using cookie-based authentication then it's getting bypassed from Rate Limiting.

      Workaround

      Using personal access token: PAT

            Unassigned Unassigned
            7fa5e2b9af91 Arijit Banerjee
            Votes:
            3 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated: