Unable to upgrade addon Edited

I'm getting a nondescript error when trying to upgrade an addon:


Confluence: 6.5.0

Addon: HTML Elements (From 2.1.0 to 2.4.0)


The 'Check the logs' message is not super helpful so far.  The only thing so far I've found in the logs is the following:




2017-11-06 17:22:03,117 WARN [http-nio-8090-exec-9] [common.security.jersey.XsrfResourceFilter] passesAdditionalBrowserChecks Additional XSRF checks failed for request: http://doc.localnet:443/rest/plugins/1.0/ , origin: null , referrer: https://doc.localnet/plugins/servlet/upm , credentials in request: true , allowed via CORS: false
 -- referer: https://doc.localnet/plugins/servlet/upm | url: /rest/plugins/1.0/ | traceId: 06d53558cba50671 | userName: markm

Also, I think the error I'm having about the base url has something to do with it.  We're using https behind an apache proxy, and have all the correct settings in place in confluence server.xml according to the docs.  And yet there's an internal request to the non https url.  Which might be causing the problem?


     <Connector port="8090" connectionTimeout="20000" redirectPort="8443"
                maxThreads="48" minSpareThreads="10"
                enableLookups="false" acceptCount="10" debug="0" URIEncoding="UTF-8"
                protocol="org.apache.coyote.http11.Http11NioProtocol" proxyName="doc.localnet" proxyPort="443" schema="https" secure="true"/>


Edited to add screenshots:




Also... Upgrades problems with addons (and the base url error) are new.  We didn't have problem ever when running confluence 6.2.1

1 answer

1 accepted

0 votes
Accepted answer
Ann Worley Atlassian Team Nov 07, 2017

Please see Cross Site Request Forgery (CSRF) protection changes in Atlassian REST

Per the error message you found, Confluence is seeing the request as coming from: http://doc.localnet:443/rest/plugins/1.0/ and the referrer as https://doc.localnet/plugins/servlet/upm. Since the port is different there is a cross site scripting error preventing you from updating the plugin.

I noticed a typo in the server.xml snippet in your description:

schema="https" should be scheme="https"

If that typo is in the actual server.xml it may be causing problems with the proxy support.



This was the issue.

Suggest an answer

Log in or Sign up to answer
Community showcase
Posted Monday in Confluence

Organizing your space just got easier - Page Tree Drag & Drop is here

Hi Community! I’m Elaine, Confluence Product Manager. You may have read my earlier post about page tree in space navigation sidebar. I'm excited to share another improvement that helps you organize ...

101 views 3 4
Join discussion

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you