Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-25773

Groups with no "Browse Users" Permission are Able to Select Assignees During Issue Creation

    XMLWordPrintable

Details

    • Bug
    • Resolution: Obsolete
    • Medium
    • None
    • 4.3, 4.4, 6.3.4, 6.3.6
    • Operating System: Ubuntu 11.04
      Java(TM) SE Runtime Environment (build 1.6.0_26-b03)
      Database: MySQL 5.1.54

    Description

      State of problem:

      1. A user (Developer) was created in JIRA and assigned to a new group (Development).
      2. Development group is given the permission to Assign Issues and Assignable User.
      3. Development group is also given the project Roles Administrators, Developers and Users.
      4. Attempt to create an issue in JIRA. The user Developer is able to assign issues to another user.
      5. Go to GreenHopper's Agile page, and create a new card. Attempt to assign the issue to another user. This results in a failure since the group Development is not given the global permission Browse Users.
      6. Go back to Administration, and assign the Development group to the Browse Users global permission.
        • Before:
        • After:
      • Go back to Agile, and attempt to assign a user to a new card. This time, you can browse the list of users.

      Which begs the question: if a group is not given the permission to Browse Users, how is he able to assign issues to users in JIRA? Is this intentional?

      We understand that GreenHopper doesn't allow this as it respects the Browse Users permission, but can the same be said of JIRA?

      Attached is a screen-cast video of the entire replication process: http://dl.dropbox.com/u/3233473/jra25573_screencast.mpeg

      Attachments

        1. project_roles.png
          project_roles.png
          29 kB
        2. permission_scheme.png
          permission_scheme.png
          14 kB
        3. create_issue_in_JIRA.png
          create_issue_in_JIRA.png
          50 kB
        4. create_issue_in_Agile_02.png
          create_issue_in_Agile_02.png
          21 kB
        5. create_issue_in_Agile_01.png
          create_issue_in_Agile_01.png
          20 kB
        6. browse_users_permission_02.png
          browse_users_permission_02.png
          11 kB
        7. browse_users_permission_01.png
          browse_users_permission_01.png
          8 kB

        Issue Links

          Activity

            People

              Unassigned Unassigned
              jalex Justin Alex [Atlassian] (Inactive)
              Votes:
              3 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: