Uploaded image for project: 'Jira Align'
  1. Jira Align
  2. JIRAALIGN-1795

[JIRAALIGN-1795] Time Tracking: User Attributes Export requires more permissions than necessary

    XMLWordPrintable

Details

    • 2
    • Severity 2 - Major
    • Batman! - TART6

    Description

      Issue Summary

      The Time Tracking User Attributes Export requires the role to also have the Administration -> People toggle enabled. This grants non-admin users the ability to administer the entire user base so should be decoupled.

      Steps to Reproduce

      1. Enable time tracking and set the users up appropriately
      2. Turn off the Administration -> People toggle
      3. Under Time Tracking -> Team, enable User Attributes Export report
      4. Impersonate/login and go to Time Tracking -> User Attributes Export
      5. No options required, click Export

      Expected Results

      Users with the permissions granted under Time Tracking role toggles are able to export the report

      Actual Results

      "Whoops....You need more access to view this page" message

      Workaround

      For the role that the user(s) is a member of, toggle on Administration -> People. Please be aware that this will also grant said users access to the People administration pages.

      Attachments

        Issue Links

          Activity

            People

              tdavenport@atlassian.com Tony D.
              cjeggo Chris Jeggo (Inactive)
              Votes:
              2 Vote for this issue
              Watchers:
              7 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Backbone Issue Sync