-
Bug
-
Resolution: Not a bug
-
Low
-
None
-
1
-
Severity 3 - Minor
-
0
-
Issue Summary
Anonymous users are able to reach the /issues/?filter=-<id> for sites without authenticating to access the page.
Steps to Reproduce
- In an incognito window, access the URL of a site's All issues filter (sitename.atlassian.net/issues/?filter=-4)
- Note that, while issues should not appear unless the Browse issue permission is set for public access, the page is still visible/reachable
Expected Results
A window containing an inaccessible message should be displayed, similar to browsing to /jira/filters for a given site:
Actual Results
The page loads and includes links for other system filters, but doesn't explicitly deny users from accessing the page:
Workaround
Currently there is no known workaround for this behavior. A workaround will be added here when available
- relates to
-
JRACLOUD-40787 It should be possible to restrict access to the Issue Navigator by anonymous users
- Gathering Interest