-
Bug
-
Resolution: Fixed
-
Low
-
None
-
10.102.3
-
1
-
Severity 3 - Minor
-
No
Issue Summary
Story Maps allows a user who has no access to Portfolio A, Program A, Agile Team A to change the parent Feature of Stories belonging to Portfolio A, Program A, Agile Team A
This is even with Story Maps Save permissions set to DISABLED.
Steps to Reproduce
Permissions for User B.
Program > Track > Story Maps ENABLED
Program > Track > Story Maps > Save DISABLED
Program > Features ENABLED
Program > Features > Child permissions all DISABLED
Conditions:
- User B does not have membership/access to Portfolio A or child Program A or child Agile team A - all under portfolio A.
- User B is a Member of Portfolio B, child Program B and Agile Team B, all under portfolio B.
- Story Map A for Stories in Portfolio A is already created (by another user, eg User A).
Steps
- Login as User B
- StoryMapGrid.asp displays all StoryMaps regardless of settings of top tier configuration bar or team permissions for Portfolios/Programs/AgileTeams
- Story Map A is visible, so click on the map icon
(Note that clicking on the name of the Story Map opens a Details Panel but "spins" and throws up a 403 unauthorised error on EditStoryMapSetup.asp) - ViewStoryMap.asp shows the Stories belonging to Portfolio A (regardless of settings of top tier configuration bar or team permissions for Portfolios/Programs/AgileTeams)
- User B can click on "Group Into Feature"
- User B can select Stories belonging to Portfolio A
- Click on Create Feature
- Add New Feature From Story Map window appears
- Fille in the Name & Description
- Program choices are only Programs that User B has access to, eg Program B
- Program Increment choice is only what User B has access to
- Click Save
Expected Results
User B should not be able to view or edit Story Map A.
User B should not be able to change the parent Feature of Stories belonging to Portfolio A
Actual Results
Stories from Portfolio A/Program A are saved as children of a new Feature in Portfolio B.
Even though the user who took the actions has no access to Portfolio A/Program A, according to team membership permissions.
Workaround
None.
- relates to
-
JIRAALIGN-3745 STORY MAPS – Save Enabled - Save button does not exist even though permission is turned on.
-
- Closed
-
-
JIRAALIGN-3746 STORY MAPS - Save Enabled - "Configure Map" - Columns can be altered but not saved
-
- Closed
-
-
JIRAALIGN-3747 STORY MAPS - Save disabled - Add Story Map button is still visible
-
- Closed
-
-
JIRAALIGN-3748 STORY MAPS - Save disabled - Configure Story Map still visible
-
- Closed
-
-
JIRAALIGN-3749 Story Maps - Save Disabled - Add/Edit/Delete rows/columns still visible and click through
-
- Closed
-
-
JIRAALIGN-3750 Story Maps - Save Enabled - Adding a new story redirects to Story Grid
-
- Closed
-
-
PS-85626 Loading...
- is connected to
-
JALPM-1560 Loading...
-
JAWM-3548 Loading...