I am attempting to configure a portal that has multiple knowledge bases attached such that I can present relevant knowledge to users based on their role or department. All customers to the portal are employees, and I had planned to put them into groups that gave them JSM Customer access to the JSM project and then adding view access in Confluence as appropriate.
To test, I connected two spaces to the project, one of which does not provide view permissions in Confluence.
Settings in the JSM project:

Space settings in Confluence:

I would expect that a portal customer wouldn't be able to view knowledge articles from the restricted space at all, but when one of the users accesses the space in the portal, they are able to see them:

They also appear in search results:

When the user selects, they see that they don't have access:

Is this expected behavior? Firstly, it's a terrible customer experience as they're searching for help, not having any indication of whether the results are even viable. Secondly, the fact that the user can see the article preview could be problematic if there are any sensitive docs published.
If there's another way to finagle the permissions setup, I'd love to know, as this will keep us from scaling out our usage of JSM.