FE-2273 implemented a check where the list of "all users" in the Crowd application was filtered by the authorized-groups returned by Crowd.
The problem is, the Directories associated with an Application in Crowd can be marked "allow all users", and we don't check for that.
We need a better way to ask Crowd for the list of all users visible by this Application.
- is caused by
-
FE-2273 Unauthorised users created on trusted request from JIRA when user is not in authorised group
- Closed