[JIRA] (JENKINS-59624) Disable Scan Organization for users that are not authorized to do so - GitHub Branch Source

2 views
Skip to first unread message

andretmcarmo@gmail.com (JIRA)

unread,
Oct 2, 2019, 10:28:04 AM10/2/19
to jenkinsc...@googlegroups.com
André Carmo created an issue
 
Jenkins / Improvement JENKINS-59624
Disable Scan Organization for users that are not authorized to do so - GitHub Branch Source
Issue Type: Improvement Improvement
Assignee: Unassigned
Components: github-branch-source-plugin
Created: 2019-10-02 14:27
Environment: 2.5.3
Priority: Minor Minor
Reporter: André Carmo

Hi,

The GitHub Branch Source plugin implements the feature of `Scan Organization`, which basically scans a whole organization for GitHub repositories and updates them in Jenkins.

 

This is useful but usually we hit the API rate limit. I know that are are issues to handle this. However, the fact that everyone is able to click on `Scan Organization Now`, is a problem because usually only the Jenkins admins are aware of this. In big organizations, with hundreds of people using Jenkins (as users, not admins) this impacts.

 

Current behaviour

Everyone is able to click on `Scan Organization Now`.

 

Proposed behaviour

Only admins or people with specific role should be able to activate that feature.

There are a couple of implementations:

  • Only admins should be able to trigger that feature
  • Only users with Configure permission should be able to trigger that feature
  • We could create a new permission type and only users with that permission type should be able to trigger that feature

 

Add Comment Add Comment
 
This message was sent by Atlassian Jira (v7.13.6#713006-sha1:cc4451f)
Atlassian logo
Reply all
Reply to author
Forward
0 new messages