FAQ › Projects

Restricting the users who can view a Redmine project

Created on 2024-09-05  •  ISHIHARA Yukiko

The users who can access the information in a project depend on the Redmine settings. In principle, users can access the information in projects of which they are members. However, depending on the settings of the project or of Redmine, users who are not members of the project, or users who are not logged in, can also view it.

With the right settings, the people who need the information can view it even if they are not registered as members of the project. This is convenient. However, with the wrong settings, unrelated third parties can access the information, especially if the Redmine server is on the Internet. You need to understand the meaning and the effect of the settings well.

Settings related to who can view a project

"Public" in the "Settings" → "Project" page of the project

If this item is turned on, the project is a public project. All users can view it, whether or not they are members of the project.

If Redmine is not configured to require authentication ("Authentication required" in the "Settings" → "Authentication" page is "No, allow anonymous access to public projects"), all users who can reach the Redmine web pages can access the project without authentication.

With the default settings of Redmine, new projects are created as public projects ("New projects are public by default" in the "Administration" → "Settings" → "Projects" page).

"Authentication required" in the "Administration" → "Settings" → "Authentication" page

If this item is set to "Yes", Redmine always requires authentication for access to its information.

If it is set to "No, allow anonymous access to public projects", the information in public projects can be accessed without authentication.

Summary of Redmine settings and who can view a project

Project Authentication required Who can view the project
Public Yes All users who are logged in to Redmine
No Anyone (login is not required)
Private Yes Only users who are logged in to Redmine and are registered as members of the project
No

Settings for using Redmine on the Internet

When you use Redmine on a server on the Internet, in most cases people who do not have a user account in Redmine must not be able to view the information.

In such cases, make the following settings in the "Administration" → "Settings" → "Authentication" page, so that unrelated people cannot access the information or register as users.

  • [Required] Authentication required: Yes
  • [Recommended] Self-registration: disabled
  • [Recommended] Allow password reset via email: off

Related information