The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

atlassian&keycloak SLO(single logged out) error

김민주
November 1, 2024

 

Hello.

Currently, both keycloak and Jira are operating in http environments.

However, sso is done smoothly by linking keycloak and jira. However, problems arise in logout.

For example, if only one client is logged in and logged out, it works normally.

However, if you log in multiple clients (e.g., bitbucket, confluence) and log out of double bitbucket, it does not log out of jira and confluence. The reason is that the keycloak session is single logged out works well, but it doesn't log out because it has its own sessions of jira and confidence left. I want to solve this problem. Maybe because of http, the basic authentication method of Jira is not disabled either.

1. Keycloak's front channel logout function does not work with the latest browser either.(i think because of CSP)

2. Keycloak's back channel logout function does not work because it does not know the atlasian.xsrf. token or JSESSIONID of the jira itself.

 

*The connection of jira and keycloak used the plug-in of the Atlasian marketplace.

*jira version is 7.13.8 and my keycloak version is 25.0.2.

1 answer

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

0 votes
Martin Runge
Community Champion
July 19, 2026

Hi @김민주

I would set the plugin's logout URL to point to Keycloak's end-session endpoint and move everything to HTTPS, since plain HTTP blocks the logout cookies and CSP does its own.

Was this ever solved on your side, and if so, what fixed it?

Cheers, Martin

TAGS
AUG Leaders

Atlassian Community Events