Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Customers can see other customer's requests.

Mario P
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
November 25, 2024

Hi,

Customers can see other customer's request which poses a security/information issue. People sending IT requests are able to see HR requests if they edit the number of the issue in a link, for example: link.to./servicedesk/customer/portal/180 <- if I change this to 179 as a customer I get to see another ticket.

I tried the following:

The following settings are applied:

Project settings > Access > People and Access:

Private - Only admins and people with internal access can search for, view and comment on this project.

Project settings > Access > Customer Permissions:

Customers can search for other customers within their organizations.

Product settings > Configuration > No, don't share email requests with the customer's organization. Requests sent from the portal will not be shared unless the customer selects otherwise

 

Effect:

User CANNOT see other requests - which is desirable, however they cannot search for ANY user in the "include users" field. We see "No users found" in the field.

 

If I change this setting:

 

Project settings > Access > People and Access:

Open - Anyone with internal access to the organization can search for, view and comment on this project.

Effect:

User CAN see other requests - which is NOT desirable, however they can search for ANY user in the organization.

 

Optimal scenario:

Users CANNOT see the requests from others BUT can include ANY user in the organization.

Does anyone have an idea how to approach this?

1 answer

0 votes
Alex Koxaras _Relational_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
November 25, 2024

Hi @Mario P and welcome to the community,

Change the setting to "Customers can search for other customers within their project or organizations" and channel access to "restricted". See if that resolved your issue.

Mario P
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
November 26, 2024

This almost works.

Now the customer won't see the other tickets if they visit the ticket link and they can select another customer in 'participants' fields.

It is not air tight though, if the customer logs in through https://domain.atlassian.net and then selects the project they are part of... they can see ALL of the tickets in the kanban board.

It's the 'issues' page and the target is just a customer - I have double checked in the admin panel.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
STANDARD
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events