My first post!
I've got Jira and Confluence configured to authenticate users via SAML SSO plugin. The two applications sit on different servers and have different URLs. They share the same user base.
If I authenticate to Jira alone, the activity stream cannot show the images from Confluence. See attached image... pretty ugly.
On the other hand, if I also authenticate to Confluence (which given the SSO is simple and fast) then the images are shown correctly in the same Jira feed.
The problem is that I cannot expect my users to login to both applications before looking at the Jira Activity Stream...
I also cannot provide anonymous access to Confluence due to implementation requirements.
I also do not want to filter out/hide Confluence activities from the feed.
Do you see a way out?
Thank you :)
Hi Stefano,
we have done some further investigations and we were able to reproduce your issue. It seems like this is a known bug with the Activity Stream gadget, which is already reported here: https://jira.atlassian.com/browse/JRASERVER-29397
Even without SAML SSO plugins installed, we were able to reproduce the same behavior. Unfortunately we didn't find a way to force SSO for the Activity Stream gadget to correctly load images. Our SAML SSO plugin uses a servlet filter to identify login requests/attempts to start the authentication process via HTTP Redirects afterwards. Perhaps there is a specific URL, which could be forced for SSO, to load images in the Activity Stream gadget. But there is no URL known to us. Furthermore it is also questionable, whether the SAML authentication can be performed at all, within the gadget loading process.
Have a nice weekend!
Christian
Hi Stefano,
as you are using our plugin - we'll look into it. Today is a bank holiday, so it'll be sometime tomorrow.
Generally I would expect this to be happening via the Application Links, which would negate the requirement of having to be authenticated on the Confluence side.
Can you confirm your Application Links are setup & working without any problems? (Which I assume they do, otherwise the Activity Stream probably wouldn't work at all).
Cheers,
Christian
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Stefano,
similar issue here. I even thought that this would be solved by using an SSO solution. I suspect that the user image URLs are pointing directly to the Confluence server & no (automatic) signon is triggered when retrieving these images.
Best
JP
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.