Task assign/unassign email notifications bypass page restriction checks — sent to users without view access

XMLWordPrintable

    • 1
    • Severity 3 - Minor

      Issue Summary

      When a task checkbox is checked or unchecked on a page with view restrictions (direct or inherited from a parent page), email notifications are sent to users who do NOT have view access to that page.

      Steps to Reproduce

      1. Create a space restricted to specific individuals
      1. Create a page with view restrictions (explicit user list)
      1. Create a child page (inherits parent restrictions)
      1. Add a task on the child page and assign it to User A (who has access)
      1. Unassign or reassign the task (toggle the checkbox)
      1. Result: User B (who does NOT have view access) receives an email notification about the task change
      1.  

      Expected Results

      Task assignment/unassignment notifications should validate the recipient's view access before sending — consistent with how @mention notifications already suppress emails for users without page access.

      Actual Results

      Users without view access receive email notifications containing the task description, page title, space name, and a "View page" link they cannot access.

      Workaround

      n/a

              Assignee:
              Yulduz Sciarrillo
              Reporter:
              Alejandra Herrera
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: