Hi community,
I have a use case that requires a JSM Project to allow anyone to raise a request. What are the community views on the risks involved?
Atlassian recommend not using this unless unavoidable...
...and here is the security advice:
Does anyone have experience of using this option and any tips to enhance security other than those detailed in the screen grabs provided?
Thanks,
Tom
HI @Tom Brown I recommend public signup for JSM:
With public signup enabled, agents can invite new customers to a service project, and new customers can create accounts on the Customer Portal and through email. Enabling public signup for your service project also enables a honeypot technique which helps prevent spambots from creating accounts through the customer portal.
You must first enable public signup at the system level:
After enabling public signup, we recommend that you also enable verification emails. This adds security to your Jira instance and makes sure that all customers are exactly who they say they are. This option should be enabled by default unless you haven't configured outgoing email.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.