Users with View and Build permissions should not be able to disable Plans, Branches and Jobs

XMLWordPrintable

    • Type: Suggestion
    • Resolution: Done
    • 6.4.1
    • Component/s: Permissions
    • None

      A user with only View and Build permissions can navigate to a completed build's page, select a job for that build and then click on Actions >> Disable Job to disable that job. It is also possible to disable a Plan from the Plan Summary page and a Plan Branch. That should require Edit capability at minimum.

      This is also not logged to the Plan Configuration >> Audit log page, so there's no way to trace a user that disabled a plan or branch via the UI. The only information that is logged in the Audit log page in the latest versions of Bamboo is related to the job being enabled/disabled.

            Assignee:
            Unassigned
            Reporter:
            Bruno Rosa
            Votes:
            13 Vote for this issue
            Watchers:
            14 Start watching this issue

              Created:
              Updated:
              Resolved: