@nerdmachine: regardless of what the help on “Logged-in users can do anything” may suggest, it is a true security policy and it means that any operation requiring authentication—even GET requests which do produce any “records” to keep—must be accompanied by a valid login token.

I do not know much about the Windows service; someone who understands this code will need to evaluate how it should be provided with an API token. Without any special (Windows-specific) tool you can always download a *.jnlp file, run it manually, and when prompted ask to save it as a service; this is just a feature of Java WebStart.

Change By: Jesse Glick (09/Jan/13 4:54 PM)
Summary: Slaves  cannot connect  forbidden  to  master through  request  JNLP  after upgrading  anonymously but no clear way  to  1.498  pass API token
Labels: jnlp regression security slave
Environment: 1.498+, Windows Server 2008 R2
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira

Reply via email to