-
Suggestion
-
Resolution: Won't Do
-
None
-
None
-
1
-
NOTE: This suggestion is for JIRA Server. Using JIRA Cloud? See the corresponding suggestion.
It is the case with all OnDemand instances that some screens can be displayed without loggin in (if someone knows the the instance address). They don't expose much information, but still, the company logo (if added) is there, as well as the fact that JIRA Agile is active:
- https://<instance>/secure/RapidStart.jspa
- https://<instance>/secure/Dashboard.jspa
Privacy-wise, it would be better if any anonymous user that shouldn't have access to the instance was automatically redirected to the login page upon attempting to open the above screens.
- relates to
-
JRASERVER-42626 Sensitive information displayed in anonymous REST API calls
- Closed
-
JRACLOUD-41493 Some screens are visible to anonymous users
- Gathering Interest