Sensitive information displayed in anonymous REST API calls

XMLWordPrintable

    • 6.04

      Expected behavior

      Block sensitive information from being displayed on anonymous REST API calls in JIRA.

      Actual behavior

      • Users' full-name are displayed when running the calls below:
        /user/picker?query=<username>
        /groupuserpicker?query=ali&showAvatar
        
      • Default fields and custom fields are displayed when running the call below:
        /jql/autocompletedata
        

      Workaround

      There's no current method for working around this within JIRA itself. The only solution would be to setup IP filtering on affected calls.

              Assignee:
              Oswaldo Hernandez (Inactive)
              Reporter:
              Joao Palharini (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              10 Start watching this issue

                Created:
                Updated:
                Resolved: