Confluence
  1. Confluence
  2. CONF-16925

Users who have no view permissions in Confluence should not see the details of other users in Confluence.

    Details

    • Type: Improvement Improvement
    • Status: Open
    • Resolution: Unresolved
    • Affects Version/s: 2.10.3, 4.2.1
    • Fix Version/s: None
    • Component/s: Permissions
    • Environment:

      N/A

    • Last commented by user?:
      true

      Description

      A user who only has access to a single group in Confluence can see the details (email and user name) of all other users in the system.

      So, for instance, user A is only in group X. User B has a personal space, but they close off all view permissions to user A and group X. In this case, user A can still see user B's details in the people list.

      The desired behaviour in this case is that User A can not see user B at all.

        Issue Links

          Activity

          James Matheson created issue -
          Roy Krishna [Atlassian] made changes -
          Field Original Value New Value
          Workflow Quality Review Flow [ 183822 ] Conf Bug Quality Review WorkFlow [ 239942 ]
          Matt Ryall [Atlassian] made changes -
          Workflow Conf Bug Quality Review WorkFlow [ 239942 ] Confluence Bug Workflow [ 318232 ]
          David Black [Atlassian] made changes -
          Remote Link This issue links to "Wiki Page (Extranet)" [ 14029 ]
          David Black [Atlassian] made changes -
          Remote Link This issue links to "Wiki Page (Extranet)" [ 14094 ]
          David Black [Atlassian] made changes -
          Link This issue is related to CONF-21292 [ CONF-21292 ]
          David Black [Atlassian] made changes -
          Labels verified
          Vitaly Osipov [Atlassian] made changes -
          Issue Type Bug [ 1 ] Improvement [ 4 ]
          Workflow Confluence Bug Workflow [ 318232 ] Confluence Default Workflow [ 380953 ]
          Priority Minor [ 4 ]
          Rank (Obsolete) 47890000000
          Vitaly Osipov [Atlassian] made changes -
          Summary Users who have no view permissions in Confluence can still see the details of other users in Confluence. Users who have no view permissions in Confluence should not see the details of other users in Confluence.
          Affects Version/s 4.2.1 [ 25893 ]
          Component/s Permissions [ 10310 ]
          Component/s Security [ 12160 ]
          Anatoli Kazatchkov [Administrative Account] made changes -
          Workflow Confluence Default Workflow [ 380953 ] New Confluence Default Workflow [ 472486 ]
          Bill Arconati [Atlassian] made changes -
          Labels verified external_wikis verified

            People

            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:
                Last commented:
                2 years, 1 week, 1 day ago