-
Suggestion
-
Resolution: Answered
-
None
-
None
-
None
Problem Definition
Currently in Bitbucket Server, a user who has administrative permissions in the application can switch between normal user operations and administrative operations without being prompted for their password. This is a potential security risk, and JIRA and Confluence do provide these extra prompts.
Suggested Solution
A popup should appear when switching to the administrative interface, asking the user for their password, much like it is implemented in JIRA and Confluence.
Workaround
Log into Bitbucket Server as a normal user with reduced privileges for normal work and log in with an administrative user when administrative work is required.
- is duplicated by
-
BSERV-12551 Implement secure administrator sessions (websudo) in Bitbucket
- Closed