I am planning to disable token checking using
Will this lead to any security issues or vulnerabilities?
Hey there, Prathighantam.
As far as I am concerned, the security issue that you will need to be concerned of is the fact that your JIRA instance will be vulnerable to XSRF (https://en.wikipedia.org/wiki/Cross-site_request_forgery) attacks. This prevent users being tricked into unintentionally submitting malicious data. Apart from that, I am not sure what other security issues is posed after you disable it.
You need to look at it in terms of your risk/reward profile. What's your user base, is it small & trusted group or large & public. Is the information valuable? What would happen if it was stolen?
and what's the reason for turning it off? Is it worth the extra risk. Atlassian put this code there for a reason. Is there another way around this? Are you trying to use Jira in a way that it shouldn't be used?
Connect with like-minded Atlassian users at free events near you!Find a group
Connect with like-minded Atlassian users at free events near you!
Unfortunately there are no AUG chapters near you at the moment.Start an AUG