Using cURL this is the response that I get:
$ curl -H "Accept: application/json" -H "Content-Type: application/json" -u 'username:password' -I 'https://mysite.com/confluence/rest/api/content/111111' -v* Trying <ip>:443...
* Connected to <mysite> (<ip>) port 443 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* successfully set certificate verify locations:
* CAfile: C:/##################
* CApath: none
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.2 (IN), TLS handshake, Certificate (11):
* TLSv1.2 (IN), TLS handshake, Server key exchange (12):
* TLSv1.2 (IN), TLS handshake, Server finished (14):
* TLSv1.2 (OUT), TLS handshake, Client key exchange (16):
* TLSv1.2 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.2 (OUT), TLS handshake, Finished (20):
* TLSv1.2 (IN), TLS handshake, Finished (20):
* SSL connection using TLSv1.2 / ECDHE-RSA-AES128-GCM-SHA256
* ALPN, server accepted to use http/1.1
* Server certificate:
<>
* SSL certificate verify ok.
* Server auth using Basic with user 'username'
> HEAD /confluence/rest/api/content/11111? HTTP/1.1> Host: mysite.com
> Authorization: Basic ################
> User-Agent: curl/7.74.0
> Accept: application/json
> Content-Type: application/json
>
* Mark bundle as not supporting multiuse
< HTTP/1.1 401
HTTP/1.1 401
< Server: openresty
Server: openresty
< Date: Thu, 04 Mar 2021 12:29:25 GMT
Date: Thu, 04 Mar 2021 12:29:25 GMT
< Content-Type: text/html;charset=utf-8
Content-Type: text/html;charset=utf-8
< Connection: keep-alive
Connection: keep-alive
< X-ASEN: SEN-####
X-ASEN: SEN-####
< Set-Cookie: JSESSIONID=#######################; Path=/confluence; HttpOnly
Set-Cookie: JSESSIONID=#######################; Path=/confluence; HttpOnly
< X-Seraph-LoginReason: AUTHENTICATED_FAILED
X-Seraph-LoginReason: AUTHENTICATED_FAILED
< WWW-Authenticate: OAuth realm="https%3A%2F%2Fmysite.com%2Fconfluence"
WWW-Authenticate: OAuth realm="https%3A%2F%2Fmysite.com%2Fconfluence"
< Content-Language: en
Content-Language: en
< Strict-Transport-Security: max-age=31536000; includeSubdomains
Strict-Transport-Security: max-age=31536000; includeSubdomains
<
* Connection #0 to host mysite.com left intact
If I go directly to my site and force using basic auth (https://mysite.com/confluence/rest/api/content/111111?os_authType=basic), after entering credentials it gives me a very weird looking 401 error (not the same as when using wrong credentials, but
This page isn’t working
If the problem continues, contact the site owner.
HTTP ERROR 401
with a reload button, and after I click on it or refresh the page it gives me exactly what I wanted to get with curl, looks like it's starting a session and passing JSESSIONID as in cookie based auth not basic auth)
As I understand, the problem is somewhere in the server setup, but I have no clue where to even begin to look. Any suggestions?