-
Bug
-
Resolution: Unresolved
-
Medium
-
None
-
1
-
Severity 2 - Major
-
4
-
Issue Summary
The Get bulk permissions API returns incorrect result in some cases, because it lacks particular checks, such as product specific permission overrides. Meanwhile, the Get my permissions API returns correct result.
Steps to Reproduce
- Create Jira Discovery Project
- Settings → Access. Set Project Access to Open
- Settings → Access → Add people. Invite User and set access level as Contributor
- User Management → Users. Chose previously added user, Grant Access to Jira product with product role set to User
- Login by a user, access project in UI, verify user cannot create issues.
- Call Get Bulk Permission endpoint.
Expected Results
Call Get Bulk Permission endpoint, expect no access to CREATE_ISSUES
Actual Results
- Call Get Bulk Permission endpoint: it shows the user has access to CREATE_ISSUES, which is not expected.
- Call My permissions endpoint: it shows the user does not access to CREATE_ISSUES, which is expected.
Workaround
Use Get my permissions API instead, but bad performance for bulk operation.
- relates to
-
GORD-544 Loading...