I just received a question from a user. He was able to make a change as "Anonymous", i.e. without being logged in.
We use LDAP authentication, and the users should be required to login. Do you have a quick idea where I may have made incorrect settings? Normally, anonymous users should be able to look but not touch.
His description of the actions taken, and a screenshot of the result:
I managed to reopen an issue as an anonymous:
http://atsrnd05.spin.local:8080/browse/SEMEKOGS1-709
Anonymous made changes - Today 11:00 Integrated [ 5 ] -> Open [ 3 ].
This is really bad 
Session timed out, and I didn't notice, I wanted to reopen anyway, so no harm was done .
