-
Bug
-
Resolution: Duplicate
-
Low
-
None
-
None
-
None
-
None
NOTE: This bug report is for JIRA Server. Using JIRA Cloud? See the corresponding bug report.
Summary of bug
When accessed via direct URL, even users who are not logged in to JIRA are able to view the JQL results page, and it does not redirect to the login page.
Steps to reproduce
- Log in to JIRA, and perform a search
- Copy down the URL of the search result. An example of this from my own instance would be : http://10.60.2.107/jira61/issues/?jql=issuekey%20%3D%20TEST-6
- Log out, and try accessing the URL
You would be able to view the results page. However, you should not be able to view the search results (as long as the appropriate project permissions are set)
Additional Info
If the 'Detail View' is selected, then the user would be redirected to the login page.
- duplicates
-
JRASERVER-34914 Issue Navigator Accessible by anonymous users.
- Closed
- is related to
-
JRASERVER-40787 It should be possible to restrict access to the Issue Navigator by anonymous users
- Gathering Interest
- relates to
-
JRACLOUD-36544 JIRA search page does not redirect user to the login page
- Closed