Hello,
I dont know why but anonymous users are having access to my on demand jira without being logged in. Also they can comment to issues etc. I looked over the permissions and there is no permission for group "anyone".
so i dont know how to revoke the public access, do you have an idea?
best regards
If people can comment/update without being logged in, then you definitely have allowed "anyone" access in the permission scheme. Are you sure you are looking at the right scheme for that project?
Also, the other place people can do this is in the workflow. If you have transitions in your workflow, then by default, ANYONE can use them. Until you explicitly add conditions to them to stop them doing it. I tend to just stick "must be role of user" into every transition to begin with.
It's very common for people to miss this - I didn't realise for the first six or seven workflows I constructed!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.