Uploaded image for project: 'Bitbucket Data Center'
  1. Bitbucket Data Center
  2. BSERV-10994

Users with access to repo can see admin settings for that repo

    XMLWordPrintable

Details

    Description

      Accessing the following specific URLs as a user who has only read access to a repository can see repository settings if they specifically use the following URLs

      {BITBUCKET_URL}/projects/{PROJECT_SLUG}/repos/{REPO_SLUG}/settings/merge-checks
      {BITBUCKET_URL}/projects/{PROJECT_SLUG}/repos/{REPO_SLUG}/settings/hooks
      {BITBUCKET_URL}/projects/{PROJECT_SLUG}/settings/merge-checks
      {BITBUCKET_URL}/projects/{PROJECT_SLUG}/settings/hooks
      

      Expected Outcome:
      Users receive a 401

      Actual Outcome:
      Users can see the checks and hooks. When you attempt to change them you receive a permissions error

      Attachments

        Issue Links

          Activity

            People

              khughes@atlassian.com Kristy
              alevinson Aaron
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: