Details
-
Suggestion
-
Resolution: Won't Do
-
None
-
None
-
None
-
2
-
Description
NOTE: This suggestion is for JIRA Server. Using JIRA Cloud? See the corresponding suggestion.
At the moment there is no way to hide a users username from other users. This is especially a problem in case of anonymous access. Any user can access the instance and view the username of the other users. This exposes one of the credentials needed to login - username. After that, one only needs to determine the password.
There are a few methods to hide the username from the UI, but it is still available in the HTML source of the page.
This is needed for security reasons.
Attachments
Issue Links
- is related to
-
JRASERVER-44932 Anonymous users able to search for JIRA users from issue navigator
- Closed
- relates to
-
JRASERVER-71899 Usernames are exposed in the URL while accessing user profiles
- Gathering Impact
-
ID-8339 Username visible to anonymous users
- Gathering Interest