Missing User Profile restriction? User are always able to guess URL of others and reach their profil

Wolfgang Landes
Contributor
September 13, 2021

Hello,
Am I right that Admins can not deny users to reach the user profile of other users by guessing the url?

Example:

A non-admin Jira user can just change the "&name=" property in the url of the public profile following the same account syntax (name.surname) and check if a member of the competing company also has an account in the jira instance.

Is there a way to restrict this?

0 answers

Suggest an answer

Log in or Sign up to answer