The picker function in /rest/api/2/user/picker allows an anonymous user to conduct queries. If a valid username is queried, the application provides details about the user to include their email address.
The API documentation available here: https://docs.atlassian.com/software/jira/docs/api/REST/6.2/ states that this method cannot be accessed anonymously. Furthermore, the 'anyone' group has been removed from the 'Browse Users' permission in the global permissions, yet the issue persists.
Please assist in restricting the ability of the anonymous user to conduct picker queries through the API.