`CAPTCHA_CHALLENGE` on login with Python JIRA

Viewed 2028

Test script:

from jira import JIRA

user_name = "my username"
password = "my password"
jira_conn = JIRA(server='http://my.server.com',
                basic_auth=(user_name, password))


Error:

jira.exceptions.JIRAError: JiraError HTTP 403 url: http://my.server.com/rest/api/2/serverInfo
    text: CAPTCHA_CHALLENGE; login-url=http://my.server.com/login.jsp
    
    response headers = {'X-AREQUESTID': '1036x605910x1', 'X-XSS-Protection': '1;mode=block',
                        'X-Content-Type-Options': 'nosniff',
                        'X-Frame-Options': 'SAMEORIGIN',
                        'Content-Security-Policy': "frame-ancestors 'self'",
                        'X-ASEN': 'SEN-2105411', 'Set-Cookie': 'JSESSIONID=3D489D7D7A533761610029A9FEBEDE83; Path=/; HttpOnly',
                        'X-Seraph-LoginReason': 'AUTHENTICATION_DENIED',
                        'WWW-Authenticate': 'OAuth realm="http%3A%2F2Fmy.server.com"',
                        'X-ASESSIONID': '161938n',
                        'X-Authentication-Denied-Reason': 'CAPTCHA_CHALLENGE; login-url=http://my.server.com/login.jsp',
                        'Content-Type': 'text/html;charset=UTF-8',
                        'Transfer-Encoding': 'chunked', 'Date': 'Mon, 29 Jun 2020 15:16:49 GMT'}
    response text = 
  1. The first time I got this error I went to a browser, logged off then in again and in addition to user+password, a captcha was asked.

    1.1. Login page asked for this captcha a few times (this is not necessarily surprising) and finally succeeded.

  2. Now I can log in and out from my JIRA server as many times as I want and it works at first in browser.

  3. No matter the conditions I try, this simple code is no longer able to log in (and it was working perfectly until a day before).

    1.1. I tried changing basic_auth to auth. No luck.


Questions:

curl -X POST http://my.server.com/jira/rest/auth/1/session -H jira/rest/auth/1/session -d '{ "username": "my username", "password": "my password" }'

but response is:

<h1>Oops, you&#39;ve found a dead link.</h1>

How can I find the correct URL for my.server.com?

  • Which additional info is relevant here.
  • What else can I test?

Environment

  • Python 3.8 and Python 2.7.
  • Py-jira: jira>=2.0.0
  • Client is Rwindows-10.
  • JIRA server version: Atlassian Jira Project Management Software (v8.3.1#803002-sha1:00bd3db)

Thanks!


EDIT*

I managed to make curl work simply like this:

curl -X POST 'http://my.server.com' --data '{ "username": "my user", "password": "my password" }'
1 Answers

In my vim plugin vira we did find using the basic_auth as the quickest way along with adding in an extra async_ option. However, I believe the issue will be that you need to verify your login through the browser or program.

In other words once you fail to login through the code you will need to confirm you are not just code trying to login, it is the same as if you failed to login through the browser enough times in a row.

We have this issue while developing as well and simply open the browser, login, enter the hard to read text and try again. Once your code is stable it is not an issue until the next issue.

Depending on the sever as well you may need the API token vs your Password. I have another example of that on my README for Atlassian cloud projects.

     # verify: will set ssl verification requirements (should be True by default)
           
        if 'https://' not in server.lower():
            server = 'https://' + server
        try:
            self.jira = JIRA(
                    options={
                        'server': server,
                        'verify': cert_verify,
                    },
                    basic_auth=(username, password),
                    timeout=2,
                    async_=True,
                    max_retries=2)
        except JIRAError as e:
            if 'CAPTCHA' in str(e):
                print(e)

JIRAError is quite useful for catching/printing the error in details.

if 'CAPTCHA' in str(e): catch CAPTCHA

Related