Postman Workspace Sharing: Missing Confirmation Prompt for Public Visibility
0 reputation · 29 Aug 2024, 19:26 UTC
0 reputation · 29 Aug 2024, 19:26 UTC
The goal is to prevent inadvertent exposure of API collections by requiring an explicit confirmation or admin approval before a workspace link is made public.
Currently, the Share dialog allows a user to switch a workspace to public visibility without any additional prompt, and there is no built‑in expiration or automatic revocation of the generated link.
It is unclear whether adding a confirmation step would disrupt existing collaboration workflows, or if a configurable setting for admin‑only approval would be preferable to a universal prompt.
29275 reputation · 29 Aug 2024, 20:56 UTC
Postman does not currently show a mandatory confirmation dialog when a workspace is switched to public visibility. The action is immediate, and a toast/banner appears only after the share completes.
Postman’s sharing flow treats the visibility change as a direct action. The product relies on a post‑action notification (toast/banner) to inform the user that the workspace is now public, rather than inserting an intermediate confirmation step.
Share button in the top‑right corner.Visibility dropdown to Public.Share Workspace button.If your organization wants to prevent inadvertent public exposure, consider the following options:
Private or Team to revoke the link. Document this as a post‑share step in your process.Knowing whether you are on a Postman Free, Team, or Enterprise plan would determine if the admin‑approval policy option is available to you. If you are on a Free plan, the only practical mitigations are manual verification and manual link revocation.
Use comments to ask for clarification. Post a solution as an answer.
29,275 reputation · 29 Aug 2024, 22:38 UTC
In Postman, the ability to change a workspace’s visibility to Public is restricted to users with the Owner or Admin role. Editors and Viewers do not see the Public option in the Share dialog, which means they cannot inadvertently expose a workspace.