Hi,
I want to call our Jira Server REST API via Javascript. I add the following filter for CORS in the web.xml:
<filter>
<filter-name>CORS</filter-name>
<filter-class>com.thetransactioncompany.cors.CORSFilter</filter-class>
<init-param>
<param-name>cors.supportedHeaders</param-name>
<param-value>Accept, Authorization, Origin, Content-Type, X-Requested-With</param-value>
</init-param>
<init-param>
<param-name>cors.supportedMethods</param-name>
<param-value>GET, POST, HEAD, OPTIONS, PUT, DELETE</param-value>
</init-param>
</filter>
<filter-mapping>
<filter-name>CORS</filter-name>
<url-pattern>/rest/*</url-pattern>
</filter-mapping>
But now I get a 403 - XSRF check failed Error. Has anyone an idea what I am missing? My request looks like the following:
var issueUrl = "https://jira.server.com/rest/api/2/issue/";
var client = new XMLHttpRequest();
client.open("POST", issueUrl);
client.setRequestHeader("Content-Type", "application/json");
client.setRequestHeader("Authorization", "Basic " + btoa(username + ":" + password));
client.onload = function () {
};
var jsonData = JSON.stringify(data);
client.send(jsonData);
I found an answer to set the Request Header "X-Atlassian-Token" to "no-check". But I think, this is not for request via browsers.
My Jira version is 8.5. Thank you for help!