-
Type:
Bug
-
Resolution: Fixed
-
Priority:
High
-
Component/s: Onboarding - nth user
-
None
-
4
-
Severity 2 - Major
-
95
Issue Summary
Creating a "Live Docs page" enables the creation of Invitation Links at the organizational level. Although the Invitation link is not easy to guess, still this poses a security risk.
Steps to Reproduce
- Check the Invitation Links and disable them from this page: https://admin.atlassian.com/o/\{org-id}/app-access-settings > Invitation links
- Add a live doc Page in your Confluence site, once it's saved
- Check the status of the Invitation links from here: https://admin.atlassian.com/o/\{org-id}/app-access-settings >
Expected Results
- Live doc should not override the org admin setting for https://admin.atlassian.com/o/\{org-id}/app-access-settings >Invitation links
- If Live Doc can't work without enabling this, we should ask the org admin to allow it to or inform the org admin about this.
Actual Results
- Invitation link for Conf here: https://admin.atlassian.com/o/\{org-id}/app-access-settings > Invitation links gets enabled
Workaround
- Manually turn off the Invitation links after creating the live doc (very difficult to turn them off after every time a live doc is created)
- mentioned in
-
Page Loading...