-
Suggestion
-
Resolution: Unresolved
Issue Summary
Currently, even if the Allow project administrators to manage project rules is unchecked, project admins can still browse automation rules from "Project Settings > Automation", this includes global rules if they change the Scope filter.
This can be a security concern, as some rules may include sensitive data such as API tokens.
Suggestion
If the setting Allow project administrators to manage project rules is unchecked, the project admins shouldn't be able to see any rules at all. Alternatively, if another option that we could check/uncheck aimed directly at project admins' ability to see rules was added, it would also be a valid solution.