Uploaded image for project: 'Advanced Roadmaps'
  1. Advanced Roadmaps
  2. JPOSERVER-383

Accessing Portfolio Administration shows login page

This issue belongs to an archived project. You can view it, but you can't modify it. Learn more

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Won't Fix
    • Icon: Medium Medium
    • None
    • 1.9.6
    • None

      Summary

      JIRA Portfolio does not allow non administrator users to manage the Portfolio » Administration page when Secure Administration Sessions (WebSudo) is enabled.

      Environment

      • JIRA 6.4.5
      • JIRA Portfolio 1.9.6

      Steps to Reproduce

      1. Setup JIRA with JIRA Portfolio
      2. Create a new user (e.g. "projectmaster");
      3. Create a new group for the Administrators of Portfolio (e.g. "jira-portfolio-administrators");
      4. Add "projectmaster" to "jira-portfolio-administrators";
      5. Navigate to Portfolio » Administration and add the "jira-portfolio-administrators" group to the Administrator role.
      6. Log in with the "projectmaster" user;
      7. Try to access *Portfolio » Administration;
      8. A login page will be displayed, stating the the user does not have permission to view page.

      Expected Results

      The user should be able to see the Portfolio Administration page.

      Actual Results

      The user would is redirected to the "WebSudo" screen, which is redirecting the user to the Login page (as the user is not an administrator and hence should not see the websudo page).

      Workaround

      Follow the Configuring Secure Administrator Sessions to disable websudo.

            Unassigned Unassigned
            mfernandes@atlassian.com Matheus Fernandes
            Archiver:
            atibrewal@atlassian.com Aakrity Tibrewal

              Created:
              Updated:
              Resolved:
              Archived: