The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

XSRF check failed after pasting license key on 6.1.2.

Guenter SolyMar
March 5, 2018

Community hint on "base URL" already checked. See screenshot.

 

1 answer

1 accepted

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

2 votes
Answer accepted
AnnWorley
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
March 5, 2018

Hi Guenter,

Do you have a reverse proxy in front of Confluence? If so, please make sure the proxy support is included in the connector directive in the <Confluence_Install>/conf/server.xml file: Proxy Support

The proxyName and proxyPort attributes can be used when Tomcat is run behind a proxy server. These attributes modify the values returned to web applications that call the request.getServerName() and request.getServerPort() methods, which are often used to construct absolute URLs for redirects. Without configuring these attributes, the values returned would reflect the server name and port on which the connection from the proxy server was received, rather than the server name and port to whom the client directed the original request.

For example change:


<Connector port="8090" connectionTimeout="20000" redirectPort="8443"
maxThreads="48" minSpareThreads="10"
enableLookups="false" acceptCount="10" debug="0" URIEncoding="UTF-8"
protocol="org.apache.coyote.http11.Http11NioProtocol" />

to include the proxy settings:

<Connector port="8090" connectionTimeout="20000" redirectPort="8443"
maxThreads="48" minSpareThreads="10"
enableLookups="false" acceptCount="10" debug="0" URIEncoding="UTF-8"
protocol="org.apache.coyote.http11.Http11NioProtocol"

proxyName="docs.avisia.org"
proxyPort="443"
scheme="https" />

Please see Cross Site Request Forgery (CSRF) protection changes in Atlassian REST for descriptions of conditions that will trigger an XSRF error.

I look forward to hearing whether the server.xml changes help or if you are using a reverse proxy.

Thanks,

Ann

Guenter SolyMar
March 5, 2018

Hi Ann,

Thank you for your fast help and solving my issue.

Yes, I am using IIS as a proxy in front of Confluence and I only miss in the server.xml the proxy ‘scheme’ tag.
Thanks a lot for this!

Regards

Guenter.

AnnWorley
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
March 5, 2018

I am very happy to hear the issue is resolved! Thanks for the good news. :)

TAGS
AUG Leaders

Atlassian Community Events