|
|
|
[
Permlink
| « Hide
]
Bob Swift - 19/Nov/05 08:00 AM
Great plugin, but normally we don't allow anonymous remote access. We do share user profiles between Jira and Confluence. I assume it is the searching that requires the authority - anonymous would not find anything important.
Same here - we cannot accept anonymous remote api use and are using shared accounts. I've been asking for SSO between Jira and Confluence ever since Confluence came out and I'd really like to see all access between the apps use the account data from whomever is using the plugin at the time.
Please add my support for this request. Confluence and Jira have a very strong permission model. However, to make this plugin function, you have to discard all of Confluence's ACLs and make everything anonymously viewable!
Surely one of the benefits of having both products from the same manufacturer should be exactly this sort of integration!
Bumping this issue to see if there's any chance of progress on getting it authenticating.
There was just a developer's blog post about trusted communication between jira and confluence for the jira-issues macro. Can that implementation also be adapted for this plugin?
http://blogs.atlassian.com/developer/2007/11/trusted_communication_between.html Hi Jeff,
Yes – that's the plan. As soon as all that work has completed and stabilized, we'll try to adapt his plugin to use the same technique. -Jonathan Hi guys,
Thought I'd bump this issue up to see if any progress has been made to address the security risk raised here. Thanks. |
|||||||||||||||||||||||||||||||||||||||||||||||