Postman Workspace Sharing: Missing Confirmation Prompt for Public Visibility
26.5K reputation · 29 Aug 2024, 19:26 UTC
Postman Workspace Sharing: Missing Confirmation Prompt for Public Visibility
The goal is to prevent inadvertent exposure of API collections by requiring an explicit confirmation or admin approval before a workspace link is made public.
Currently, the Share dialog allows a user to switch a workspace to public visibility without any additional prompt, and there is no built‑in expiration or automatic revocation of the generated link.
It is unclear whether adding a confirmation step would disrupt existing collaboration workflows, or if a configurable setting for admin‑only approval would be preferable to a universal prompt.
- Should Postman introduce a mandatory confirmation dialog when changing a workspace’s visibility to public?
- Would an optional team‑level setting that requires admin approval for public shares better balance security and usability?
- Is there a need for an automatic expiration or revocation mechanism for public workspace links?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 29 Aug 2024, 22:38 UTC
In Postman, the ability to change a workspace’s visibility to Public is restricted to users with the Owner or Admin role. Editors and Viewers do not see the Public option in the Share dialog, which means they cannot inadvertently expose a workspace.
- Open a workspace and check your role under Settings → Roles.
- If your role is Editor or Viewer, the Visibility dropdown will only show Private and Team options.
- Only when the role is Owner or Admin does the Public option appear, and selecting it proceeds without a confirmation prompt.