[JIRA] (JENKINS-59568) Users can use system credentials although they don't have permission

2 views
Skip to first unread message

pablo.gomezjimenez@dhl.com (JIRA)

unread,
Sep 28, 2019, 5:19:03 AM9/28/19
to jenkinsc...@googlegroups.com
Pablo Gomez created an issue
 
Jenkins / Bug JENKINS-59568
Users can use system credentials although they don't have permission
Issue Type: Bug Bug
Assignee: Unassigned
Components: credentials-plugin
Created: 2019-09-28 09:18
Environment: Jenkins 2.164.3
Credentials plugin 2.1.18
Priority: Critical Critical
Reporter: Pablo Gomez

Hi, we have our Jenkins configured with  Project-based Matrix Authorization Strategy. I recently removed for normal users all Credentials permissions because I don't want them to be able to use the system credentials store. I want them to use the folder credentials store instead. Now users cannot see the credentials option in the main menu, only inside their folders. However, when they need to add some credential to their jobs (i.e. in SCM configuration), they still can select the credentials in the system store. My expectation is that they can only select the credentials in the folder store.

Add Comment Add Comment
 
This message was sent by Atlassian Jira (v7.13.6#713006-sha1:cc4451f)
Atlassian logo
Reply all
Reply to author
Forward
0 new messages