-
Suggestion
-
Resolution: Unresolved
-
None
-
None
Actual behavior: When a link to an issue with a security level assigned is posted to a channel by a user that has access to the issue, it is unfurled exposing issue details to all channel members, while some of them may have no access to the issue in Jira. If the user doesn’t have access to the issue - it isn’t unfurled.
Suggestion:
The app should stop sending unfurls for all issues that have any security level assigned or the preview shouldn't be available for the users that don't have access to the issue.
Add the ability to disable previews for issues with the security level.
We're affected by this. It's so easy for a user to unintentionally paste a link in the wrong place and reveal data to others that shouldn't see this.