Conflunce "Anonymous User" can still see restricted information, user names and also, post blogs

XMLWordPrintable

    • Type: Bug
    • Resolution: Handled by Support
    • Priority: Highest
    • Component/s: Confluence
    • None
    • Environment:

      Internet Public Access

      Reference Confluence OnDemand
      site. contentserv.atlassian.net
      Hi,

      for business reason, we would like to offer a multiple user account for access to our Knowledge Base. It would be good if we could restrict access to the "Profile" for a user (in the Download version I believe one can!) and remove the rights to "People and Space Directory", again business results.

      As Atlassian is not offering these restriction features in the OnDemand (please confirm!!), we have decided to use the anonymous access. This does not fit our business needs, but it appears that we have no other choice.

      That having been said, this "anonymous" access does not appear to hide Confluence "Space" Administrator or Content creator names. The Space "Administrators" name is shown in the "Space Details" GUI and the anonymous user has access to "Extras", which includes the pages history. On the page history GUI, the content creator names are displayed. In both cases, an anonymous person has access to privilege information and can use it for abuse.

      Also, an anonymous user appears to be able to create a "Blog", which does NOT make sense as the user is anonymous. These system settings appears to be encouraging trouble and abuse.

      An anonymous user should not have rights to access user names nor create Blog content!!!

      Can you help us here? This is important as we may have to drop Confluence as our Knowledge Base source!

      please let us know,

      gerry

              Assignee:
              Unassigned
              Reporter:
              G
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: