Uploaded image for project: 'Bamboo Data Center'
  1. Bamboo Data Center
  2. BAM-3413

Bamboo "Watcher" notifications should go through a permission check

    XMLWordPrintable

Details

    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

    Description

      If a user has marked a plan as their favourite ad then their permissions are changes so they can't see the plan, the user is still picked up as a Watcher for that plan.

      There may be a similar problem where if an invalid user commits code to a build they will also recieve notifications via the "Committers" recipient.

      Example from support case:
      For instance if a user watches a plan and has enabled notifications in his profile - notifications will be sent even if the user 'leaves the building' This is a potential breach and 'inactive' users should be blocked from notifications through group/user permissions.

      The only way to stop is to edit the user's profile and disable sending notifications.

      Attachments

        Issue Links

          Activity

            People

              achystoprudov Alexey Chystoprudov
              ukuhnhardt Ulrich Kuhnhardt [Atlassian]
              Votes:
              6 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: