-
Type:
Bug
-
Resolution: Tracked Elsewhere
-
Priority:
Medium
-
Component/s: User Management - Directory - Manage Product Access
-
None
-
1
-
Severity 3 - Minor
Issue Summary
Community does not yet have a good way to correctly honor the profile picture privacy settings that can be set on https://id.atlassian.com/manage-profile/profile-and-visibility
Steps to Reproduce
- In https://id.atlassian.com/manage-profile/profile-and-visibility
- Upload a profile picture
- For the field of "Who can see your profile photo?" choose an option such as "Only my Organization" (this requires a managed Atlassian account, it's not something you can replicate with a gmail address account which is unmanaged).
- Go to community, check your profile or look at any post you have created on the site
Expected Results
End user expects that their photo would not be visible to anonymous users or users outside their org.
Actual Results
Community shows this photo to everyone, regardless if they are in your org or not.
Workaround
- Delete Profile Avatar Image
- Privacy settings Default to “Anyone”
- Wait 15 minutes for synchronization between Identity and Community to occur
- Set profile to “Create Initials Avatar”
- Set Profile Privacy setting to [Company Name]
- Wait 15 minutes for synchronization between Identity and Community to occur
- Upload a new Avatar Image
- Set Privacy to [Company Name] only
- Wait 15 minutes for synchronization between Identity and Community to occur