-
Type:
Suggestion
-
Resolution: Unresolved
-
None
-
Component/s: Permissions, Security
-
None
-
0
-
1
Problem Definition
Anonymous access is enabled by default for new Bamboo installations
Suggested Solution
Have anonymous access disabled by default.
Why this is important
With the setting enabled, many pages can be accessed without logging in. This could show Bamboo configurations and results to people outside of the organization, potentially creating security issues.
Workaround
An admin can deselect/uncheck "Access" for Anonymous users under Admin > Overview > Global permissions and Deployment projects, as follows:
Site access and Builds
- Navigate to Admin >> Overview >> Global permissions
- Scroll down to the Anonymous users row (Under Other)
- Deselect the "Access" checkbox
Deployments
- Navigate to Deploy >> All deployment projects
- For each Project:
- Click the Edit (pencil) icon next to one of its Environments
- Click the Project permissions button
- Scroll down to the Anonymous users row (Under Other)
- Deselect the "View" checkbox