Details
-
Suggestion
-
Resolution: Fixed
-
0
-
Description
Basically, if you allow Project Administrators to manage automation rules, they have the ability to impersonate every user in a Jira environment.
This feature can be used to "impersonate" every single user in a Jira environment, and it may be used to complete tasks that were not considered when this feature was developed.
Therefore, it would be wise to consider a method of limiting this ability, allowing project administrators to only select users from a subset of the entire environment's user base.