Uploaded image for project: 'Bitbucket Data Center'
  1. Bitbucket Data Center
  2. BSERV-20063

When an unlicensed user attempts to clone or push a repository using a valid SSH key, the "Last authenticated" field on the Users page is updated.

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Medium Medium
    • None
    • 9.4.0
    • SSH
    • None

      Issue Summary

      When an unlicensed user tries to clone or push a repository using an SSH key(added in the user profile), the "Last authenticated" field on the Users page is updated, even if the user lacks any permissions in Bitbucket.

      Steps to Reproduce

      • Create an SSH key and add it to a user's profile in Bitbucket.
      • Remove the user from the global permissions page to make it unlicensed.
      • Attempt to clone a repository from Bitbucket using the SSH key. Although the clone will fail, the "Last authenticated" field on the Users page will still be updated.

      Expected Results

      The "Last authenticated" field should only be updated when the user is properly authenticated and has the necessary permissions to carry out that specific task.

      Actual Results

      Due to lack of permissions, the clone or push operation fails, which is the correct behavior. However, the "Last authenticated" field is updated, which might lead an administrator to believe that an unlicensed user without any permissions performed a task in Bitbucket using the SSH key.

      Workaround

      Currently there is no known workaround for this behavior. A workaround will be added here when available

              Unassigned Unassigned
              83b3279fad28 Aman Shrivastava
              Votes:
              1 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: