Remove GitLab for Jira Cloud app cookie authentication code
For guidance on the overall deprecations, removals and breaking changes workflow, please visit Breaking changes, deprecations, and removing features
Deprecation Summary
The GitLab for Jira Cloud app currently supports two types of authentication:
- Cookie-based authentication. If users are logged in on GitLab, the GitLab for Jira Cloud app can use the session cookie. Since the app is rendered in an iframe, this has limitations on some browsers and won't for self-managed users.
- OAuth. The app retrieves an access token via OAuth flow that will be used to authenticate the users
We announced the Cookie-based authentication in %15.0. The removal can start in %16.0.
Implementation steps:
- Default enable or remove [Feature flag] Clean up Jira Connect OAuth (#355048 - closed)
- Remove frontend code (plan described here)
- Documentation changes as described in #403627 (comment 1349584088) and #403627 (comment 1349598355). Documentation changes are necessary to complete this issue.
Once this issue is complete, users will no longer be able to use cookie-based authentication to access the GitLab for Jira Cloud app. Instead, they will need to use OAuth authentication.
Breaking Change
Self-managed users should configure their instance to use OAuth authentication for Jira.
Affected Topology
Self-managed.
Affected Tier
- Free
- Premium
- Ultimate
Checklists
Labels
-
This issue is labeled deprecation, and with the relevant ~devops::
,~group::
, and~Category:
labels. -
This issue is labeled breaking change if the removal of the deprecated item will be a breaking change.
Timeline
Please add links to the relevant merge requests.
- As soon as possible, but no later than the third milestone preceding the major release (for example, given the following release schedule:
14.8, 14.9, 14.10, 15.0
–14.8
is the third milestone preceding the major release):-
A deprecation announcement entry has been created so the deprecation will appear in release posts and on the general deprecation page. https://docs.gitlab.com/ee/update/deprecations.html#cookie-authorization-in-the-gitlab-for-jira-cloud-app -
Documentation has been updated to mark the feature as deprecated.
-
-
On or before the major milestone: A removal entry has been created so the removal will appear on the removals by milestones page and be announced in the release post. - On the major milestone:
-
The deprecated item has been removed. -
If the removal of the deprecated item is a breaking change, the merge request is labeled breaking change.
-
Mentions
-
Your stage's stable counterparts have been @mentioned
on this issue. For example, Customer Support, Customer Success (Technical Account Manager), Product Marketing Manager.- To see who the stable counterparts are for a product team visit product categories
- If there is no stable counterpart listed for Sales/CS please mention
@timtams
- If there is no stable counterpart listed for Support please mention
@gitlab-com/support/managers
- If there is no stable counterpart listed for Marketing please mention
@cfoster3
- If there is no stable counterpart listed for Sales/CS please mention
- To see who the stable counterparts are for a product team visit product categories
-
Your GPM has been @mentioned
so that they are aware of planned deprecations. The goal is to have reviews happen at least two releases before the final removal of the feature or introduction of a breaking change.
Deprecation Milestone
15.8
Planned Removal Milestone
16.0
Links
Edited by Magdalena Frankiewicz