Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-15415

Anonymous users can browse source code through coverage report

    • Icon: Improvement Improvement
    • Resolution: Fixed
    • Icon: Major Major
    • cobertura-plugin
    • None

      This is more a suggestion than a real issue.

      When configuring Jenkins to matrix bases security, and giving anonymous users read access, they are able to browse source code throw the coverage report.
      Other plugins does not permit this (workspace is not available as default for anonymous) and for example both Task Scanner and the Warnings plugin disable the last link down to the source when not logged in.

      My use case is to let logged in users do almost anything (we give authenticated users admin rights) and users not logged in should be able to see jobs and job results - but the source code.

      I wrote a mail to the dev-list and tried to discuss it there in more generelt.
      Mail subject is: "Jenkins security setup and plugin responsibility"

          [JENKINS-15415] Anonymous users can browse source code through coverage report

          Jes Struck added a comment -

          I have created this pull reqeust to solve the issue https://github.com/jenkinsci/cobertura-plugin/pull/11

          Jes Struck added a comment - I have created this pull reqeust to solve the issue https://github.com/jenkinsci/cobertura-plugin/pull/11

          Jes Struck added a comment -

          this has been solved in the tip of the repos, so we are just waiting for the next release of the plugin

          Jes Struck added a comment - this has been solved in the tip of the repos, so we are just waiting for the next release of the plugin

          sogabe added a comment -

          fix in 1.8

          sogabe added a comment - fix in 1.8

            jstruck Jes Struck
            bue Bue Petersen
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: