Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-7467

Show only users with project access rights in Find Issues-User Browser

    • 9
    • 21
    • We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

      NOTE: This suggestion is for JIRA Server. Using JIRA Cloud? See the corresponding suggestion.

      Atlassian Update - 21 2015

      Hi everyone,

      Thanks for voting and commenting on this issue. Your feedback is key to helping us understand how you use JIRA so we can continue improving your experience. We have reviewed this issue over the last few days; however there are not currently any plans to implement this suggestion.

      Please remember that jira.atlassian.com is one of many inputs for the JIRA roadmap. You can learn more about our process here.

      I understand that our decision may be disappointing. Please don't hesitate to contact me if you have any questions.

      Regards,
      Otto Ruettinger
      Principal Product Manager, JIRA
      oruettinger (at) atlassian (dot) com

      We have different customers using our JIRA-Enterprise instance.

      If we activate the user browser on the find issues screen, all users appear in the browser.

      This is a problem for us, because users from customer company A can see users from customer company B.

      It would be nice if only users are displayed which have access to the projects the current user has access to.

            [JRASERVER-7467] Show only users with project access rights in Find Issues-User Browser

            rvdeijk added a comment -

            +1

            rvdeijk added a comment - +1

            +1

            Trinh Nguyen added a comment - +1

            +1

             

            Maxence Decanter added a comment - +1  

            +1

            Neli Steinlein added a comment - +1

            This bug is open for more than 15 years now ...

            Stefan Lohrum added a comment - This bug is open for more than 15 years now ...

            This is a critical security issue and should be solved soon.

             

            LPS Config Team added a comment - This is a critical security issue and should be solved soon.  

            A global Workaround for Systems which use nginx. You can block the search and keep Users away for searching.

            Add this to your Location Block:

                  if ($arg_fieldName ~ "assignee" ) { return 404; }
                  if ($arg_fieldName ~ "reporter" ) { return 404; }  
            

            Patrick Schneider added a comment - A global Workaround for Systems which use nginx. You can block the search and keep Users away for searching. Add this to your Location Block: if ($arg_fieldName ~ "assignee" ) { return 404; } if ($arg_fieldName ~ "reporter" ) { return 404; }

            This is an absolut critical must-have. Our security team has disabled this functionality until Atlassian comes up with a proper solution

            Rik Raspe [SDL] added a comment - This is an absolut critical must-have. Our security team has disabled this functionality until Atlassian comes up with a proper solution

            Mat A--HD added a comment -

            I see that this issue was created in 2005 and here we are 16 years later with no resolution.   

            Mat A--HD added a comment - I see that this issue was created in 2005 and here we are 16 years later with no resolution.   

            Christoph Eberhardt added a comment - - edited

            Unbelievable that this issue still exists!

            Christoph Eberhardt added a comment - - edited Unbelievable that this issue still exists!

              Unassigned Unassigned
              35ef088b9b2f Robert Schmidl
              Votes:
              425 Vote for this issue
              Watchers:
              242 Start watching this issue

                Created:
                Updated: