Uploaded image for project: 'Advanced Roadmaps'
  1. Advanced Roadmaps
  2. JPOSERVER-383

Accessing Portfolio Administration shows login page

This issue belongs to an archived project. You can view it, but you can't modify it. Learn more

    XMLWordPrintable

Details

    • Bug
    • Resolution: Won't Fix
    • Medium
    • None
    • 1.9.6
    • None

    Description

      Summary

      JIRA Portfolio does not allow non administrator users to manage the Portfolio » Administration page when Secure Administration Sessions (WebSudo) is enabled.

      Environment

      • JIRA 6.4.5
      • JIRA Portfolio 1.9.6

      Steps to Reproduce

      1. Setup JIRA with JIRA Portfolio
      2. Create a new user (e.g. "projectmaster");
      3. Create a new group for the Administrators of Portfolio (e.g. "jira-portfolio-administrators");
      4. Add "projectmaster" to "jira-portfolio-administrators";
      5. Navigate to Portfolio » Administration and add the "jira-portfolio-administrators" group to the Administrator role.
      6. Log in with the "projectmaster" user;
      7. Try to access *Portfolio » Administration;
      8. A login page will be displayed, stating the the user does not have permission to view page.

      Expected Results

      The user should be able to see the Portfolio Administration page.

      Actual Results

      The user would is redirected to the "WebSudo" screen, which is redirecting the user to the Login page (as the user is not an administrator and hence should not see the websudo page).

      Workaround

      Follow the Configuring Secure Administrator Sessions to disable websudo.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              mfernandes@atlassian.com Matheus Fernandes
              Archiver:
              atibrewal@atlassian.com Aakrity Tibrewal

              Dates

                Created:
                Updated:
                Resolved:
                Archived: