I want to give someone access to my private repository to just review the code and see it but not copy/download the code.
What access level should I grant?
Can read only access prevent downloading/copying repository?
Dear Vesh,
The following permission levels and its consequences exist within Bitbucket repositories;
So, regarding to your question.. yes, people can clone/fork/pull the repository to their local system.
Here a link to the documentation.
Friendly Regards,
Jeremy Mooiman
And does cloning/forking means actual download of the repository to the user's computer/laptop or taking the code away from bitbucket?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Dear Vesh,
Yes, a user will be able to ''clone'' the repository and thus download a repository to his/her local machine and read the files.
When you want to work on a project by updating its files or adding new files, you need to make a local clone of the remote Bitbucket repository onto your machine or local network. You do this using the Clone button from the Bitbucket repository. If you forked a repository, you simply clone the fork. If you branched a repository, you clone the repository and checkout the branch.
Friendly Regards,
Jeremy Mooiman
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
To follow up on your question that I missed during writing my answer; The three permissions;
Will all allow for code to be cloned and thus downloaded to an individual his/her system.
Your request for a user to only review code is practically the same, because some one could still copy code.
Friendly Regards,
Jeremy Mooiman
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Jeremy hits the nail on the head: If a user can read code (even without cloning the repo), there is nothing preventing them from using copy & paste to get hold of the entirety of the code after all.
Cheers,
Christian
Premier Support Engineer
Atlassian
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I understand both sides of this argument.
Sure, a user would technically be able to copy the code if they could read it - but in reality, that would be extremely laborious process, given that most projects occupy numerous files in complex directory structures.
It agree that it would be nice to be able to give a user (a prospective employer, for example) access to your code in order to assess your skill level, without making it easy for them to clone all of your existing projects.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
As an owner I would agree that having an option for just a review would be great as there are certain times where you need to share some code but want to be certain a clone is not performed. Having a way to do this would certainly be something I would pay for.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I fully agree with this, I've exactly the same request/concern.
Chris Wall is right, even it's technically possible, in reality it's will take hours to copy each of the source code compare to just download the entire repo.
As Tony Wible said, Having a way to do this would certainly be something I would pay for.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I fully endorse this feature as well. Also, the code doesn't have to be selectable, making copy/paste a nightmare (because you'd have to dig through the HTML source to extract it) or the user would have to take screencaps and re-type it.
Effectively this would reduce the prospect of someone "making off" with the code a non-starter.
Who needs to be fellated to get this feature improvement on the roadmap?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I don't see the benefit in this kind of feature. "Review" and "clone" are essentially the same given that a simple script could walk through and "review" the entire source tree and copy all of the source.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hello Team,
Does anyone get solution to give access of view code but to prevent clone or download code? We have also same requirements for the same.
We have already tried few other tools but didn't get any success it yet as per requirements.
Let me know if anyone has do it into free or premium account which will be helpful for us.
Regards,
Ritesh Prajapati
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
That privilege is for those who have a premium account, I found this...
https://confluence.atlassian.com/bitbucket/control-access-to-your-private-content-862621261.html
You can require that the users with access to private content are only able to see the content if they've enabled two-step verification. If they haven't enabled two-step verification, users with access will see a message that prompts them to enable it. In addition to being unable to see this content, users won't be able to clone, push, or pull a private repository either.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I believe 2-step verification does not help achieve the result I (and others above) are looking to achieve. We want a user to be able to view the code, but not to clone / copy / duplicate / print it. Password-protected Adobe Acrobat files, and some websites, provide exactly this capability.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I agree, we are already using 2 steps authentication, that doesn't fix the issue, that just allows to protect access to you BitBucket Cloud not to manage permission for people that have access.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I agree, it doesn't help much. We need capability to control copy/clone under read-only access to prevent insiders code exfiltration.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.