You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Confluence已登录状态下外部应用调用REST API授权方案咨询

Awesome question! Let’s walk through this step by step since you’re already logged into Confluence and need to authenticate your external web app’s API calls without exposing user credentials.

1. Can You Use a Session ID for Authorization?

Absolutely! If you’re already logged into Confluence in the browser, your active JSESSIONID cookie can be used to authenticate REST API requests. Confluence uses this cookie to recognize your logged-in session. A few things to note:

  • Same-origin vs. Cross-origin: If your external app is on the same domain as Confluence, this works out of the box. For cross-domain requests, you’ll need Confluence configured to allow CORS (more on that later) and your Ajax call must include withCredentials: true to send the cookie.
  • Session limits: The session ID will expire when you log out or the session times out, so this is best for short-lived, user-bound actions.

2. How to Get a REST Access Token

You have two solid options here, depending on your use case:

Option A: Personal Access Token (PAT)

This is the most reliable method for long-term or non-user-bound access. Here’s how to generate one:

  • Log into Confluence, click your profile avatar in the top-right → select Personal settings
  • From the left menu, choose Personal access tokens
  • Click Create token, give it a name, set an expiration date, and check the permissions you need (for attachments, write:attachment is key)
  • Copy the generated token immediately—you’ll only see it once! Store it securely.

Option B: XSRF Token (for same-domain apps)

If your app is on the same domain as Confluence, you can grab the XSRF token from the current page’s metadata to validate POST/PUT/DELETE requests:

const xsrfToken = document.querySelector('meta[name="ajs-xsrf-token"]').content;

3. Ajax Call Examples

Let’s adjust your sample code to work with both authorization methods, specifically for uploading attachments (since that’s your end goal):

Using Session ID (Same Domain or CORS Configured)

// Replace {pageId} with your target Confluence page ID
$.ajax({
  url: "http://localhost:1990/confluence/rest/api/content/{pageId}/child/attachment",
  method: "POST",
  xhrFields: {
    withCredentials: true // Critical to send the JSESSIONID cookie
  },
  headers: {
    // Use XSRF token if same-domain, or "no-check" if allowed by Confluence settings
    "X-XSRF-Token": document.querySelector('meta[name="ajs-xsrf-token"]').content
  },
  // Attachments require FormData—replace with your form element ID
  data: new FormData(document.getElementById('attachment-upload-form')),
  processData: false, // Don't let jQuery process the FormData
  contentType: false, // Let the browser set the correct multipart header
  success: function(response) {
    console.log("Attachment uploaded successfully!", response);
  },
  error: function(xhr) {
    console.error("Upload failed:", xhr.responseText);
  }
});

Using Personal Access Token (PAT)

PATs use Basic Auth—you can leave the username blank and use the token as the password:

const pat = "your-personal-access-token-here";
const authHeader = "Basic " + btoa(`:${pat}`); // Encode for Basic Auth

$.ajax({
  url: "http://localhost:1990/confluence/rest/api/content/{pageId}/child/attachment",
  method: "POST",
  headers: {
    "Authorization": authHeader,
    "X-Atlassian-Token": "no-check" // Bypass XSRF check for PAT requests
  },
  data: new FormData(document.getElementById('attachment-upload-form')),
  processData: false,
  contentType: false,
  success: function(response) {
    console.log("Attachment uploaded successfully!", response);
  },
  error: function(xhr) {
    console.error("Upload failed:", xhr.responseText);
  }
});

Key Notes

  • Permissions: Make sure the user (either the logged-in user or the PAT owner) has permission to upload attachments to the target page.
  • CORS Setup: For cross-domain requests, your Confluence admin needs to add CORS config to confluence.cfg.xml:
    <property name="confluence.webapp.cors.enabled">true</property>
    <property name="confluence.webapp.cors.allowed.origins">https://your-external-app-domain.com</property>
    <property name="confluence.webapp.cors.allowed.methods">GET,POST,PUT,DELETE</property>
    <property name="confluence.webapp.cors.allowed.headers">Authorization,X-XSRF-Token,X-Atlassian-Token</property>
    <property name="confluence.webapp.cors.allow.credentials">true</property>
    
  • Security: Never hardcode PATs in frontend code! If your app is client-side, use a backend proxy to handle API calls and keep the token secure.

内容的提问来源于stack exchange,提问作者Kateryna

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 03:47:30