Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-18076

Warn about assigning "Anyone" group in Global and Project permissions

    • 11
    • 50
    • We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

      NOTE: This suggestion is for JIRA Server. Using JIRA Cloud? See the corresponding suggestion.

      Assigning anyone to global permissions such as a "Browse user" is a sure way to shoot yourself in the foot inadvertently.

      We make a vague mention of it in the documentation

      • if you wish to grant the permission to non logged-in users, select 'Anyone' (not recommended for production systems). Note that the 'JIRA Users' permission (i.e. permission to log in) cannot be granted to 'Anyone' (i.e. to non logged-in users) since this would be contradictory.

      A worse impact can happen if 'Browse Project' (in Project Permissions page) is misconfigured for 'Anyone'. This may allow public search engine crawlers to index JIRA issues.

      We should add an explicit warning on the Global Permissions and Project Permissions page.

      Alternatively we could update the wording description like was done in JRA-29503. That is, we could change "Anyone" to "Public" (or "Anonymous and JIRA users").

            [JRASERVER-18076] Warn about assigning "Anyone" group in Global and Project permissions

            Conny Postma made changes -
            Remote Link Original: This issue links to "Page (Atlassian Documentation)" [ 92033 ]
            Alex [Atlassian,PSE] made changes -
            Remote Link Original: This issue links to "SECINT-6999 (Atlassian JIRA Extranet - Special Projects)" [ 257531 ] New: This issue links to "SECINT-6999 (Hello Jira)" [ 257531 ]
            Eduard M made changes -
            Link New: This issue was cloned as JRASERVER-74956 [ JRASERVER-74956 ]
            kitkat (Inactive) made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 631116 ]
            Lacey Teal made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 587807 ]
            Cathy S made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 571558 ]
            Parolini (Inactive) made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 549687 ]
            Adam G. made changes -
            Remote Link Original: This issue links to "Page (Confluence)" [ 540458 ]
            Adam G. made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 540458 ]
            Mike McGreevy made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 534717 ]

              mrzymski Maciej Rzymski
              andrew.myers Andrew Myers [Atlassian]
              Votes:
              76 Vote for this issue
              Watchers:
              55 Start watching this issue

                Created:
                Updated:
                Resolved: