Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-8663

Need the ability to disable the choose users from group membership form (via config file?)

    XMLWordPrintable

Details

    • Suggestion
    • Resolution: Won't Fix
    • None
    • None
    • App server: Tomcat application server 5.5.15
      JDK: Sun 1.5.0_10
      LDAP server: SunOne Directory server 5.2
      OS: Redhat Enterprise Server 3
    • We collect Confluence feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

    Description

      Use Case: Add Page : Restrictions : Choose Users
      Issue: UUIDs display instead of username (reported in CONF-8662)
      Impact: Exposure of group membership to end users violates our information security policy. This is a show stopper. Confluence will not be used in production at Brown University if this issue is not corrected.
      Analysis:
      Although it may be convenient in some organizations to be able to select individuals from a group membership list, this violates our information security policy. We need the ability to disable the Group Membership option on the User Search form when restricting access to a wiki page.

      There is a separate issue on this screen that is described in CONF-8662, that prevents the display of members' username, full name, and email address. While this doesn't matter to us if we can disable this form, it should be corrected for the sake of users who want to use this feature, but don't use an AD-type DN format.

      Attachments

        Issue Links

          Activity

            People

              matt@atlassian.com Matt Ryall
              865c34732c48 James Cramton
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: