- Using the "Edit in Word" feature opens an authentication dialog in Microsoft Word
- "Edit in Word" opens a blank document in Word and on save prompts the user to save the document as a local file.
With "Allow authentication tokens in the URL path" enabled
- The Office Connector plugin setting is set to "Allow authentication tokens in the URL path".
Use Firebug and set a breakpoint on
if (jsession)in the
jsessionidis empty and Word tries to open a document without a valid session id and the
/ocauthpath component in the path:
As of Confluence 3.3.1 the standalone distribution use the
useHttpOnly flag to mitigate the risk of client side scripting attacks. This prevents the "Edit in Word" feature of the Office Connector plugin bundled with Confluence 3.3.x from working properly.
HttpOnly cookies helps prevent client side scripting vulnerabilities. Consider using this workaround for non public instances of Confluence only.
With "Allow authentication tokens in the URL path" disabled
- You are using Windows XP SP 2, Windows Server 2003 or Windows 7
- Your Confluence installation does not use SSL (i.e. http://confluence.example.com and not https://confluence.example.com)
- The "Edit in Word" link launches Word but the document is empty or wasn't opened.
With path authentication disabled the Office Connector uses "Basic Authentication" to authenticate the user.
The following operating systems disable the use of "Basic Authentication" if the WebDAV server does not use a secure channel (this is in accordance with the WebDAV spec):
- Windows Vista
- Microsoft Windows XP Service Pack 2 (SP2) or later versions of Windows XP
- The 64-bit version of Windows XP or later versions of Windows XP
- Windows Server 2003 Service Pack 1 (SP1) or later versions of Windows Server
See Disabling Basic Authentication over a clear channel for further information.
Either ensure that your Confluence installation uses a secure channel (i.e. SSL/https) or change the registry settings to allow basic authentication over a clear channel as outlined in KB 2123563.