While researching for different approaches I wanted to make a check also from here.
We're working on a Confluence macro plugin that would open an iframe to an external service. It's clear how the user can be identified but the service would need to validate the Confluence user's session against the Confluence. What would be the best approach to valite the user's session against Confluence?