Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

After Jira restart, all users are logged out - even those with "remember my login" cookies

cweiske
Contributor
December 3, 2018

When our admins restart Jira or Confluence, all users are logged out - even when they selected "remember my login" when logging in before.

The Jira cookie page says nothing about this.

 

Why is that?

What can we do to stay logged in, even after server/daemon restart?

2 answers

1 vote
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 3, 2018

There is nothing you can do about this.

You probably don't want to either; a service that does not discard sessions when it restarts is not secure. 

David Ferbr May 19, 2019

No, that is wrong. The user does not care whether an admin has restarted the server overnight. The user experience must not be hurt by this event. It has nothing to do with "service security".

Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
May 19, 2019

I'm afraid it is.  It is a security hole to continue sessions.  You are right that the user experience is absolutely critical - "not being hacked" overrides "slightly more convenient" every time.

David Ferbr May 19, 2019

OK can you explain how exactly is it a security hole? 
What happens during the service restart that compromises the system security? 

0 votes
David Ferbr May 19, 2019

Ran into exactly the same problem. Were you able to solve this?

Suggest an answer

Log in or Sign up to answer