We're trying to configure customer access to JIRA, and don't want to display any internal project data. We've got all internal projects secured with a specific internal Permissions Scheme. After setting up the customer accounts, I logged in with one to see what they see. All projects are secured properly; however, I can search for and display the System Dashboard. That wouldn't be so bad, but on the system dashboard is the Activity Stream, showing issues from all projects. Is there a way to restrict the view of the Activity Stream, say, by jira group? Or is there another slick way that I can restict the view our external customers have of the activity stream?
Yes, I do see items (not issues) from 'secured' projects in the Stream and when I click on them I don't get any type of permission error -- for example, a code snippet that was submitted. Yes, I thought I had closed that loop with my Issue Security Scheme, but it doesn't appear to be working. :-(
I don't think so, Patrick, The Permissions and Issue Security seem to only apply to ISSUES, yes? Doesn't seem to account for items related to Bamboo, Crucible, FishEye, Subversion, and Confluence. These are the items I ended up turning 'off' on the Activity Stream so they now don't show up. Do you have a better way to filter those items by a security group?
Perhaps you could restrict the Activity Stream gadget to just logged in users. Adding the paratmeter roles-required=use to the end of the activity streams gadget URL should prevent usrs who are not logged in from seeing the gadget.
For other configurations, check out this JIRA: https://jira.atlassian.com/browse/JRA-21505
Here's an example of what I can see as an external customer in the Activity Stream:
"Ken Hymes committed changeset 3982 to the DELIRIOUS project"
There are active links to the "3892" code snippet and to the project DELIRIOUS that I can access and view.
These are links/references to our Subversion code repository, which is also linked to issues in JIRA...
Is there any update to this? How do you actually apply roles-required=use to a gadget? @David Simpson I know this is a really old issue, but having the exact same problem.
Essentially, our internet hosted JIRA application shows the Activity Stream as it is part of the System Dashboard when a user is logging in. So the before username / password has been entered the Activity Stream shows users updates on Issues and the regular activities as expected. This is fine to show after the user logs in but not before any login info is provided. How do I restrict / stop this?
Connect with like-minded Atlassian users at free events near you!Find an event
Connect with like-minded Atlassian users at free events near you!
Unfortunately there are no Community Events near you at the moment.Host an event