-
Type:
Suggestion
-
Resolution: Unresolved
-
Component/s: Identity Internal - Permissions
-
None
-
1
Issue Summary
When anonymous access is enabled in Confluence and a custom domain URL is set: If accessing Confluence from any app's sidebar (like jira.atlassian.<site>.com/jira/) or the universal app switcher (top left), a user is treated as if they have anonymous access to Confluence even if they have a different permission level.
Steps to Reproduce
- Enable anonymous access in Confluence globally and have one space with anonymous access enabled.
- Clear browser cache and cookies
- Log in to Atlassian Cloud to an account with Jira User permissions or greater and Confluence User permissions or greater.
- Navigate to some cloud site with a custom domain URL, like jira.atlassian.<site>.com/jira/
- Select Confluence in the sidebar or the app switcher in the top left.
Expected Results
A user sees all content appropriate to their permission level in Confluence
Actual Results
The user sees content as if they are an anonymous user until they click the "Login" icon in the top right of Confluence. After logging in to Confluence, if they later perform steps 1-5, then they will see their full Confluence experience and not the anonymous version.
Workaround
Users must click the "Login" icon in the top right of Confluence. Admins can alternatively deactivate their custom domain URL.
- is related to
-
CONFCLOUD-84074 Make it clear to users when browsing Confluence while logged out
- Gathering Interest
- relates to
-
CONFCLOUD-83816 Navigating to Confluence from sidebar or Atlassian Home does not always set appropriate session cookie
-
- Gathering Impact
-