Uploaded image for project: 'Bitbucket Data Center'
  1. Bitbucket Data Center
  2. BSERV-7242

Limit @ mention list to authorized users

    XMLWordPrintable

Details

    • 1
    • We collect Bitbucket feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

    Description

      It looks like the update behavior is that only licensed users will be listed with the mention, but this doesn't take the limit far enough. Users who don't have permissions to a project shouldn't be available for mentions in the context of that project. For us this is a security issue, for most, this is still bad UI. It'll only create confusion and concern from a security perspective (The inevitable question will be does this person have access to our project? Why do they show up here?). This also creates the possibility of leaking sensitive client information. We're a hosting multiple clients with this application and it would allow them to search for each other, which is a problem for us.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              28636481ddb1 Eric Rutherford
              Votes:
              2 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated: