jira-prometheus-exporter icon indicating copy to clipboard operation
jira-prometheus-exporter copied to clipboard

Add warning about publicly exposing usernames.

Open SijmenHuizenga opened this issue 6 years ago • 1 comments

Hi! Awesome work with this plugin, we use it all the time and it works superbe!

I have just one suggestion: add a notice to the top of the readme, wiki and atlassian-plugin-page that warns administrators that by default, usernames will be exposed to the public. Maybe something along the lines of:

Be aware, this plugin publicly exposes some sensitive data by default. The metrics page exposes the username of who last logged in, who last edited issues in every project and some more usernames. You should enable token protection to make sure the public cannot view usernames.

SijmenHuizenga avatar Feb 22 '19 14:02 SijmenHuizenga

Will do

AndreyVMarkelov avatar May 04 '19 08:05 AndreyVMarkelov