I'm currently trying to set up a Jira Server installation for multiple clients and while reviewing/probing the Structure plugin it worked surprisingly well initially.
But what I found was that if a user creates a structure and then goes to Configure > Permissions > User he has access to the full user list of the installation.
While all other userlists (like assignee lists or "@" lists in normal Jira are aware of the current project context and the rest of Structure seems to be aware of issue accessibility of both the current user as well as the structure creator, the permission user list simply exposes all users of the installation, which is an issue especially for us since we use mail addresses as usernames and these get exposed as well, with the mail domain essentially exposing our client list.
I understand that this is an edge case and quite hard to fix, but in my opinion there should be an additional check where only users are shown that share a project with the owner of the structure. Group sharing unfortunately does not work since everybody will share the jira-software-users group for general Jira access.