Convert to Work Item - bypassing the UI-level restriction set in the Screen Scheme

XMLWordPrintable

    • 2
    • Severity 3 - Minor
    • 2

      Issue Summary

      The "Convert to Work Item" flow in Jira Cloud allows users to edit custom fields that are explicitly excluded from the Create and Edit screens. These fields are configured to be available only on the View Screen. This flow bypasses the intended screen-level restrictions.

      Steps to Reproduce

      1. Identify or create a custom field.
      2. Configure the Screen Scheme for a project so that these fields are present only on the View Screen and removed from the Create and Edit screens.
      3. As a standard user (non-admin), locate a Sub-task or Issue.
      4. Click the ellipsis menu (three dots) in the top-right corner and select 'Convert to Work Item'.
      5. Select the work item destination that has the custom field created.
      6. The assistance displays the custom fields as editable
      7. Update the field and complete the flow.
      8. The field is updated.

      Expected Results

      Fields that are not part of the destination work item's Create or Edit screens should remain read-only during the conversion, in accordance with the Screen Scheme configuration.

      Actual Results

      The conversion dialog displays the restricted fields and allows the user to manually input or modify values, bypassing the UI-level restriction set in the Screen Scheme.

      Workaround

      As partial controls, you could:

      • From the permission scheme, restrict Edit issues and other powerful permissions to a limited set of roles (e.g. team leads, admins).
      • Use Issue Security to hide sensitive sub-tasks that should never be converted.

       

              Assignee:
              Steve Rabino
              Reporter:
              Gabriel Aguilera
              Votes:
              2 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: