Rate limiting does not work for Cookie based authorization

XMLWordPrintable

    • Type: Suggestion
    • Resolution: Unresolved
    • None
    • Component/s: Security
    • None
    • 1
    • 3

      Issue Summary

      Rate limiting does not work for Cookie based authorization

       

      This is reproducible on Data Center: Yes

      Steps to Reproduce

      1. Enable rate limiting
      2. Enable Cookie based authorization
      3. We will observe that Jira is not blocking the request if it breaches the limit 

      Expected Results

      We can see the calls are getting blocked when it uses the basic authentication but if the code is using cookie-based authentication then it's getting bypassed from Rate Limiting.

      Workaround

      Using personal access token: PAT

              Assignee:
              Unassigned
              Reporter:
              Arijit Banerjee
              Votes:
              5 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated: