Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-32386

Mail Handler unable to create attachments from email when reporter is not in the default issue security level

    XMLWordPrintable

Details

    Description

      NOTE: This bug report is for JIRA Server. Using JIRA Cloud? See the corresponding bug report.

      When a Project has a default issue security level set for all newly created issues, and a user (who is not allowed to view the issue because of the default security level set) tries to create an issue from email with attachments, the issue is created successfully but the attachments are rejected with the following error message that is added as a comment on the issue:

      Reporter (johndoe) does not have permission to create attachments in project XXXX. 
      Following attachments found in the email have been discarded:
      aaa.xlsx
      bbb.jpg
      

      This has been reproduced in a 5.1.8 instance, but isn't reproduceable in 5.2.5. now also happening on 6.3-OD-04-019

      Steps to reproduce:

      1. Create an issue security scheme in a project, with security levels restricting a particular user (reporter) from viewing the issue. Set this is as the default issue security level.
      2. Have that user create an issue via email with attachments.
      3. Observe that issue is created successfully, but permissions message is created as a comment on the issue and attachments are dropped. Untitled.jpg

      Screenshots added showing the same attachment sent via email to the same project when there is no Issue Security Scheme restricting the user (test_attachment_OK.jpeg) and later after adding Issue Security Scheme restricting the user (test_attachment_FAIL.jpeg)

      Attachments

        1. test_attachment_FAIL.jpeg
          test_attachment_FAIL.jpeg
          224 kB
        2. test_attachment_OK.jpeg
          test_attachment_OK.jpeg
          200 kB
        3. Untitled.jpg
          Untitled.jpg
          55 kB

        Issue Links

          Activity

            People

              Unassigned Unassigned
              dleng Daniel Leng (Inactive)
              Votes:
              7 Vote for this issue
              Watchers:
              16 Start watching this issue

              Dates

                Created:
                Updated: