Uploaded image for project: 'Jira Software Cloud'
  1. Jira Software Cloud
  2. JSWCLOUD-14506

Automatic access added to newly added bitbucket account without notificiation

    XMLWordPrintable

Details

    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

    Description

      Steps to replicate:

      1. Add a new bitbucket account to your JIRA OnDemand instance via the DVCS connector.
      2. Click on the cog to the right of your new account and view 'configure automatic access'

      Result:

      Automatic access will be set up and membership to the 'developers' group will be granted

      Expected result:

      Either no automatic access will be set up, or during the creation process you should be warned that automatic access has been granted.

      This is a security concern for users that add people that should have access to the repository to their OD account, as access will be granted unknowingly.

      It also becomes more of a problem now that UNIFIED-79 has been released, as it's not at all obvious that membership is granted anymore.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              mhunter Matthew Hunter
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: