Patch #27009

Updated by Toshi MARUYAMA over 1 year ago

When an administrator disabled the @login_required@ setting and/or sets projects as public, this can have grave consequences for the protection of the data in-house in hose projects. If this is done carelessly, confidential data might be exposed to undesired audiences (e.g. the global unauthenticated internet).

The attached patches try to make the consequences of these settings clearer by making them more prominent and explain their consequences to the user. This helps admins and project managers make the correct decisions.

We use these patches on "Planio":https://plan.io/redmine-hosting/ where all accounts require authentication by default. But even for "older" Redmine installations which might have some internal public projects it might still be surprising that they are suddenly public when not enforcing authentication anymore.

Back