Uploaded image for project: 'Atlassian Intelligence'
  1. Atlassian Intelligence
  2. AI-602

Do not show registered users in quick search to anonymous users

    • 2
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      NOTE: This suggestion is for Confluence Cloud. Using Confluence Server? See the corresponding suggestion.

      Registered users appears in quick search, even when it's a search made by anonymous.

            [AI-602] Do not show registered users in quick search to anonymous users

            Any news on when we and how we can disable browse user permission in quick search for Confluence? I'm not really sure if https://jira.atlassian.com/browse/CONF-7057 should have been closed as it's an important feature.

            Gajan Umapathy added a comment - Any news on when we and how we can disable browse user permission in quick search for Confluence? I'm not really sure if https://jira.atlassian.com/browse/CONF-7057 should have been closed as it's an important feature.

            Nick added a comment -

            This is particularly important for users of Service Desk like as when confluence is used with Service Desk the usernames of all our customers are displayed in the search box!

            Nick added a comment - This is particularly important for users of Service Desk like as when confluence is used with Service Desk the usernames of all our customers are displayed in the search box!

            In order to combat this we have decided to have one 10 user license that is our public confluence, and then the bigger license which is the private instance. The data in the private instance is too important and is only accessible with a VPN. Just a small suggestion to those that want a fix now.

            Ludger Peters added a comment - In order to combat this we have decided to have one 10 user license that is our public confluence, and then the bigger license which is the private instance. The data in the private instance is too important and is only accessible with a VPN. Just a small suggestion to those that want a fix now.

            We also want to keep our users' names private. We've disabled the 'view user profile' permission for anonymous users, so it seems odd they can still see the profiles in the quick search!

            Beth Aitman added a comment - We also want to keep our users' names private. We've disabled the 'view user profile' permission for anonymous users, so it seems odd they can still see the profiles in the quick search!

            Any news about this issue? Because we also don't want anonymous users to spy out our user's names.

            Herman Wander added a comment - Any news about this issue? Because we also don't want anonymous users to spy out our user's names.

            Is anything happening with this? This is a major problem for us and client confidentiality going forward, it may mean we have to take clients off the system!

            Chris Armstrong added a comment - Is anything happening with this? This is a major problem for us and client confidentiality going forward, it may mean we have to take clients off the system!

            BillA added a comment -

            reopening this as a feature request

            BillA added a comment - reopening this as a feature request

            Quite unbelievable how a bug like this stays unattended to for so long. This is a major privacy and security issue for our and any other company employing Confluence.
            Can we please have a statement by Atlassian on how and when they will address this issue?

            Martin Moser added a comment - Quite unbelievable how a bug like this stays unattended to for so long. This is a major privacy and security issue for our and any other company employing Confluence. Can we please have a statement by Atlassian on how and when they will address this issue?

            Also reproducible on 4.3.5. Users will show in quick search autocomplete even if 'View User Profiles' is disabled in Confluence Admin > Global Permissions > Anonymous Access.

            Robert Chang added a comment - Also reproducible on 4.3.5. Users will show in quick search autocomplete even if 'View User Profiles' is disabled in Confluence Admin > Global Permissions > Anonymous Access.

            This is a very important improvement to us, because we don't want anonymous users to spy out our user's names.

            Kirstin Seidel-Gebert added a comment - This is a very important improvement to us, because we don't want anonymous users to spy out our user's names.

              Unassigned Unassigned
              e9054dd7b5a7 Cédric Joly [OUTSCALE]
              Votes:
              24 Vote for this issue
              Watchers:
              18 Start watching this issue

                Created:
                Updated: