Uploaded image for project: 'Xporter for Jira'
  1. Xporter for Jira
  2. XPORTER-3540

Xporter is not getting Atlassian CSRF Token

    XporterXMLWordPrintable

Details

    • Bug
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • 6.6.0
    • 6.6.2
    • Security
    • None
    • JIRAXPORTER 2020 Sprint 2
    • OK

    Description

      Xporter is not getting Atlassian CSRF Token.

      Steps to reproduce the error:

      • Install the newest version of Xporter
      • Configure Tomcat to use HttpOnly session ID cookies 
      • Open the browser console
      • Application tab
      • Check if Atlassian.xsrf.token has httpOnly checked
      • Access Search for Issues screen
      • Try to load the Xporter dialog

       

      Steps to configure the httpOnly on every cookie:

      https://confluence.atlassian.com/jira064/preventing-security-attacks-720412500.html#PreventingSecurityAttacks-ConfiguringTomcattouseHttpOnlySessionIDCookies

      Attachments

        1. Application cookies.png
          92 kB
          Andre Fernandes Rodrigues
        2. Xporter function.png
          11 kB
          Andre Fernandes Rodrigues

        Activity

          People

            rmbr Rui Rodrigues
            afro Andre Fernandes Rodrigues
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 1 day, 1 hour
                1d 1h