Restrict access to repositories to people in team

Issue #13808 open
Renato Rudnicki
created an issue

In Bitbucket repository user and access groups the add user box auto completes with all the Bitbucket users in the world. We need to be able to restrict Bitbucket repository access to users in the team (or via email domain) so nobody outside our team can accidentally be granted access. The UI shows if a user is a team member but does not restrict it to these users.

It would be great if there was some way to only show members from the team to be added into a group or repo.

Comments (6)

  1. Alastair Wilkes staff
    • changed status to open

    Hi Jonathan,

    Thanks for your feedback. We've taken a few steps in this direction, but we need to take another look at this.

    In the meantime, Bitbucket should display a warning when adding a non-teammate to a repository. Is that warning not appearing for you?

    Thanks,
    Alastair
    Bitbucket PM

    PS - Priority of minor seems appropriate given our priority definitions, but we'll bump it up if that changes.

  2. Jonathan Le

    Hi Alastair,

    Attached a Gif where we didn't always get the warning. In the above example I disabled my Adblocker. Sometimes I'd get the warning, but sometimes I would not. In cases where Adblocker/Adgaurd is one, the warning would never appear.

    For my part, if we could get an Option to all together disable adding non-teammembers, that would be the best.

  3. Alastair Wilkes staff

    Thank you for the gif! We'll take a look at that - and talk a bit more internally about the pros and cons of adding this restriction.

    EDIT: Also, we need to look at the autocomplete issue.

  4. Log in to comment