-
Suggestion
-
Resolution: Unresolved
-
3
-
20
-
NOTE: This suggestion is for JIRA Cloud. Using JIRA Server? See the corresponding suggestion.
Currently, even if a user is not logged into JIRA, he/she will still be able to access the Issue Navigator using the URL: http://<JIRA_URL>/issues/?jql=/.
Steps to reproduce:
- Setup a JIRA instance.
- Try to go to the Issue Navigator URL (for example: http://localhost:8080/issue/?jql=)
- Even if you are not logged in, you will still be able to see the issue navigator.
There are customers who share their filters with everyone, and having the Issue Navigator URL publicly accessible allows for any user to browse those filters and see the filter owner name, for instance.
Although this is the expected behaviour, it would be helpful to have the possibility of restricting access to the Issue Navigator (e.g. in the General Settings) so that anonymous users are redirected to a login page.
- is related to
-
JRACLOUD-80245 Anonymous users can reach Jira system filter endpoints
- Closed
-
JRASERVER-40787 It should be possible to restrict access to the Issue Navigator by anonymous users
- Gathering Interest
- relates to
-
JRACLOUD-36544 JIRA search page does not redirect user to the login page
- Closed
-
JRACLOUD-34268 Issue / project not found message in issue searches for anonymous users should prompt user to login
- Closed
- mentioned in
-
Page Loading...