We're trying to configure customer access to JIRA, and don't want to display any internal project data. We've got all internal projects secured with a specific internal Permissions Scheme. After setting up the customer accounts, I logged in with one to see what they see. All projects are secured properly; however, I can search for and display the System Dashboard. That wouldn't be so bad, but on the system dashboard is the Activity Stream, showing issues from all projects. Is there a way to restrict the view of the Activity Stream, say, by jira group? Or is there another slick way that I can restict the view our external customers have of the activity stream?
Perhaps you could restrict the Activity Stream gadget to just logged in users. Adding the paratmeter roles-required=use to the end of the activity streams gadget URL should prevent usrs who are not logged in from seeing the gadget.
For other configurations, check out this JIRA: https://jira.atlassian.com/browse/JRA-21505
Activity stream should only display issues updates for the issues the logged in user can see. What happens if you click on any of the issues in the activity stream? Do you get a permission error?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Yes, I do see items (not issues) from 'secured' projects in the Stream and when I click on them I don't get any type of permission error -- for example, a code snippet that was submitted. Yes, I thought I had closed that loop with my Issue Security Scheme, but it doesn't appear to be working. :-(
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
So it looks like a mis-configuration with your permission scheme and/or issue security scheme (maybe your issues do not have a security level selected).
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I don't think so, Patrick, The Permissions and Issue Security seem to only apply to ISSUES, yes? Doesn't seem to account for items related to Bamboo, Crucible, FishEye, Subversion, and Confluence. These are the items I ended up turning 'off' on the Activity Stream so they now don't show up. Do you have a better way to filter those items by a security group?
 
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
What worked for me is restricting the permission for Developer Tools in the Permission Scheme assigned to the project. By default is assigned to all JIRA users. Changed to Project roles.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thank you very much. That's what i was looking for. Hide all activity not related to user project.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You are welcome. Glad to help
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Did not work for me. Removed all permissions from View Development Tools, but any logged user still can see any activity for all projects in Activity Stream.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
is the same for me...not working...how can I resolve this issue?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
im having the same issue
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Any update on the above ? I am still facing the same issue.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Is there any update to this? How do you actually apply roles-required=use to a gadget? @David Simpson I know this is a really old issue, but having the exact same problem.
Essentially, our internet hosted JIRA application shows the Activity Stream as it is part of the System Dashboard when a user is logging in. So the before username / password has been entered the Activity Stream shows users updates on Issues and the regular activities as expected. This is fine to show after the user logs in but not before any login info is provided. How do I restrict / stop this?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Here's an example of what I can see as an external customer in the Activity Stream:
"Ken Hymes committed changeset 3982 to the DELIRIOUS project"
There are active links to the "3892" code snippet and to the project DELIRIOUS that I can access and view.
These are links/references to our Subversion code repository, which is also linked to issues in JIRA...
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Hymes,
Did you fix this issue. I am still facing the issue. Users who don't have access to other projects still see the issues commented etc.,
thanks,
vijay
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Well, I believe that the Activity Stream gadget complies to the JIRA permissions so you should be fine. Do they see issues that they are not supposed to see on the gadget?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Yes, Tim, they do see items from projects they shouldn't see...not issues, but code changes, comments, etc. Any way to use Security to rope these off as well?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
 
 
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.