|
||||||||||||||||
|
This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrators. For more information on JIRA, see: http://www.atlassian.com/software/jira |
||||||||||||||||
You received this message because you are subscribed to the Google Groups "Jenkins Issues" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
For more options, visit https://groups.google.com/d/optout.

This is by design, as these files are logical extension of static files in the war file. Just like favicon.ico is accessible without permission check, userContent files are accessible anonymously. I've added https://wiki.jenkins-ci.org/display/JENKINS/User+Content to call attention to that.
Files that require access control should be placed under job, build, etc., which provides the ACL for access control.