Is there a way to stop the constant popup to enter admin password?

Eva
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 3, 2011

I understand this is a good security feature, but it get annoying when you ARE the admin and you have to type your password like every click. I would thought 4.4 woudl fix this problem, but I guess I was a bit too hopeful. If there is something I am missing, please let me know b/c it is driving me insane when I try to setup from workflow to fields and have to enter teh password...again.

Thanks in advance.

1 answer

1 accepted

2 votes
Answer accepted
Jeremy Largman
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
August 3, 2011

This is called websudo. Here's the documentation on how to disable it:

http://confluence.atlassian.com/display/JIRA/Configuring+Secure+Administrator+Sessions

Joe Clark
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
August 3, 2011

The purpose of the Secure Administrator Sessions feature is to help prevent XSRF attacks against administrative URLs. Please keep this in mind when disabling it! :-)

Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
August 3, 2011

When a security measure prompts the question "how do I disable it" (from a legitimate user), it's failed.

Joe Clark
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
August 3, 2011

Valid point, Nic.:-)

I wasn't trying to defend the feature from criticism, just pointing out that it does serve a purpose and that you should consciously weigh up security vs. convenience when choosing to disable it.

Microsoft still beats Atlassian on the "annoying security prompt scale", though: http://www.youtube.com/watch?v=VuqZ8AqmLPY

Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
August 3, 2011

Oh, absolutely, I don't pretend that I know a better way of doing it.

It's just I've been lectured at length on security and human behaviour recently, and that was a point that stuck. Exactly as you say, you need to weigh up the security vs convenience.

As for your comparison with Microsoft, I'm not sure it's a fair scale. The world is still waiting for Microsoft to turn out a piece of software that we can point at and say "actually, yes, that works well..."

Jim Birch
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 3, 2011

If you must, bump the timeout rather than disabling...

Eva
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 3, 2011

Again, I am not trying to sounds like whiny admin who doesnt care about security, but it just get very annoying really fast when you needs to enter password within 5 minutes since you last enter. And i know this is security feature and know that it protect me and such, but for test environment setup, this IS the showstopper for me. it get annoying too to show a demo to client and have to say, oh opps, hold on, let me put my password...again.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events