Uploaded image for project: 'Jira Align'
  1. Jira Align
  2. JIRAALIGN-4984

User can overwrite Portfolio Epic via Import despite no visibility to the Epic

      Issue Summary

      A user who has no visibility to a Portfolio and its Epics can still modify those Epics via Import. This is inconsistent with the broader UI and can lead to unintentional overwriting of data that is difficult to identify and fix.

      Steps to Reproduce

      1. Create Portfolio 1 and Portfolio 2 with a single Program under each
      2. Add Test user as member of Portfolio 2 Team
      3. Create Epic1 under Portfolio 1
      4. Log in as Test user and confirm you have no access / visibility to Epic1
      5. As Test user, perform import targeting Epic1's ID




      Expected Results

      Import should be consistent with broader UI and prevent modification of work items for which a user does not have visibility

      Actual Results

      Import allows modification of work items for which a user does not have visibility which can lead to unintended overwriting of data

      Workaround

      Currently there is no known workaround for this behavior. A workaround will be added here when available

        1. image-2023-05-10-12-52-47-922.png
          28 kB
          Brandon Harris
        2. image-2023-05-10-12-54-21-577.png
          41 kB
          Brandon Harris
        3. image-2023-05-10-12-56-38-194.png
          41 kB
          Brandon Harris
        4. image-2023-05-10-13-00-46-559.png
          26 kB
          Brandon Harris
        5. image-2023-05-10-13-08-16-475.png
          44 kB
          Brandon Harris
        6. image-2023-05-10-13-09-32-357.png
          45 kB
          Brandon Harris
        7. image-2023-05-10-13-10-28-751.png
          39 kB
          Brandon Harris
        8. image-2023-05-10-13-11-17-760.png
          68 kB
          Brandon Harris

          Form Name

            [JIRAALIGN-4984] User can overwrite Portfolio Epic via Import despite no visibility to the Epic

            backbone-sync-bot made changes -
            backbone-sync-bot made changes -
            Remote Link New: This issue links to "JAVOM-2560 (Software Teams JIRA)" [ 1033042 ]
            Rodrigo Cortez made changes -
            Remote Link New: This issue links to "PS-152485 (Atlassian Support System)" [ 832656 ]
            Josh Ellis (Inactive) made changes -
            Labels Original: Bulldog JAVOM New: Bulldog
            ja-sync-bot made changes -
            Labels Original: Bulldog New: Bulldog JAVOM
            Kirill Duplyakin made changes -
            Remote Link New: This issue links to "PS-140760 (Atlassian Support System)" [ 804913 ]
            backbone-sync-bot made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: In Progress [ 3 ] New: Closed [ 6 ]
            backbone-sync-bot made changes -
            Fix Version/s New: 10.122.3 [ 105214 ]
            backbone-sync-bot made changes -
            Status Original: Ready for Development [ 10049 ] New: In Progress [ 3 ]
            Inna Dogan made changes -
            Status Original: Long Term Backlog [ 12073 ] New: Ready for Development [ 10049 ]

              dfuller@atlassian.com Don Fuller
              1a93744f1bf8 Brandon Harris (Inactive)
              Affected customers:
              2 This affects my team
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: