We have conflicting requirements that:
- closed issues should be publicly available, so that everyone can see what is fixed
- sensitive data from customers should not be available.
The compromise that we found is that, when an issue is closed, its summary and description should be made public (after some manual check), but not comments and attachments.
Now, we need to implement this :-)
Comments can be worked out, since there is a visibility field on them, but the visibility of attachments is the same as the issue they're on. (There are several long-outstanding improvement requests related to this: JRA-6185, JRA-3893, ...)
Here are a few workarounds we could think of:
- cloning each closed issue into a public project, removing comments and attachments
- forbidding the attachments, and using a protected FTP server to store them
- removing the attachments of an issue when it's closed
- adding a proxy in front of our public JIRA, so that the nasty bits are removed from the page
- ... ?
All of this seems rather clumsy... Would you have a better solution? Or what would you consider the less ugly one?
Thanks