Uploaded image for project: 'Bitbucket Cloud'
  1. Bitbucket Cloud
  2. BCLOUD-8652

Prevent false committer attribution (impersonation) (BB-9788)

    XMLWordPrintable

Details

    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

    Description

      Bitbucket's UI automatically links commits to the Bitbucket account whose email address matches that of the committer string. However, this allows for users to accidentally or deliberately use another person's address in a commit and have that commit be attributed to this person on the site.

      To guard against this, add a button to the account settings to disable this functionality and instead perform automatic commit attribution only for repos that are owned by the account.

      Note that this does not prevent users from using incorrect committer addresses and this name and address will still show up in the UI, but it will prevent the name from linking to the account and render the user's avatar.

      Attachments

        Activity

          People

            Unassigned Unassigned
            6995b9ed1710 evzijst
            Votes:
            1 Vote for this issue
            Watchers:
            5 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: