Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-20866

Permissions - View Watchers/Voters vs. Manage Watchers/Voters - Inconsistency of visible information between JQL & issue view

    XMLWordPrintable

Details

    Description

      If a user lacks the 'View Voters and Watchers' permission but has the 'Manage Watchers'; there is an inconsistency in the visible information available via JQL and the issue view.

      For example, consider the following project's permission scheme:

      Only members of the 'jira-administrators' are able to 'View Voters and Watchers'.

      Such a user is able to do so via JQL:

      Consider a user that is not a member of the 'jira-administrators' group and lacks the 'View Voters and Watchers' permission but is a member of the 'jira-developers' group which is conferred the 'Manage Watchers' permission:

      They do not see the same list of issues as the member of the 'jira-administrators' group did via JQL:

      However, if they view the issue, they are then allowed to view the watchers because of the conferred 'Manage Watchers' permission:

      This is inconsistent with JQL where they are not allowed to view this information.

      I suggest that either JQL allows users which possess the 'Manage Watchers' permission to be able to view watchers via the watcher clause in JQL; or that 'Manage Watchers' requires the user to also have the 'View Voters and Watchers' permission.

      Attachments

        Activity

          People

            Unassigned Unassigned
            pdzwart PdZ (Inactive)
            Votes:
            3 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated: