Confluence turn off REST API

Is it possible to turn off the rest api in Confluence? We recently performed a webscan of Confluence using HP WebInpect and it reported numerous criticals due to the rest api. This could be easily resolved if I can restrict or turn off the rest api.

3 answers

1 vote

Lot of the default functionality in Confluence uses REST and hence it is not possible to disable it. Maybe you can put something like Apache in the front to prevent calls to certain urls!

I thought the REST api was just to integrate other applications with Confluence. Does Confluence itself post to the REST API?

Steven Behnke Community Champion Jun 29, 2016

Yes some functionality of the product uses the REST API.

The only thing you can disable is the "Remote API (XML-RPC & SOAP)" as described here: https://confluence.atlassian.com/doc/enabling-the-remote-api-150460.html

But it is deprecated from Confluence 5.5 on, so they will turn it of someday anyway.

 

0 votes

False positives are common from most automated security checking tools. Can you say what kind of results were found? Atlassian is most likely aware of the results from their own security checks - they use these tools too

Suggest an answer

Log in or Sign up to answer
Community showcase
Posted Oct 24, 2018 in Confluence

Atlassian Research opportunity with Confluence templates

Do you use templates with Confluence? Take part in a remote 1-hr workshop. You'll receive USD $100 for your time!   We're looking for people to participate in a   remote 1-hr workshop...

964 views 14 12
Join discussion

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you