Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-25773

Groups with no "Browse Users" Permission are Able to Select Assignees During Issue Creation

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Obsolete
    • Icon: Medium Medium
    • None
    • 4.3, 4.4, 6.3.4, 6.3.6
    • Operating System: Ubuntu 11.04
      Java(TM) SE Runtime Environment (build 1.6.0_26-b03)
      Database: MySQL 5.1.54

      State of problem:

      1. A user (Developer) was created in JIRA and assigned to a new group (Development).
      2. Development group is given the permission to Assign Issues and Assignable User.
      3. Development group is also given the project Roles Administrators, Developers and Users.
      4. Attempt to create an issue in JIRA. The user Developer is able to assign issues to another user.
      5. Go to GreenHopper's Agile page, and create a new card. Attempt to assign the issue to another user. This results in a failure since the group Development is not given the global permission Browse Users.
      6. Go back to Administration, and assign the Development group to the Browse Users global permission.
        • Before:
        • After:
      • Go back to Agile, and attempt to assign a user to a new card. This time, you can browse the list of users.

      Which begs the question: if a group is not given the permission to Browse Users, how is he able to assign issues to users in JIRA? Is this intentional?

      We understand that GreenHopper doesn't allow this as it respects the Browse Users permission, but can the same be said of JIRA?

      Attached is a screen-cast video of the entire replication process: http://dl.dropbox.com/u/3233473/jra25573_screencast.mpeg

        1. browse_users_permission_01.png
          8 kB
          Justin Alex [Atlassian]
        2. browse_users_permission_02.png
          11 kB
          Justin Alex [Atlassian]
        3. create_issue_in_Agile_01.png
          20 kB
          Justin Alex [Atlassian]
        4. create_issue_in_Agile_02.png
          21 kB
          Justin Alex [Atlassian]
        5. create_issue_in_JIRA.png
          50 kB
          Justin Alex [Atlassian]
        6. permission_scheme.png
          14 kB
          Justin Alex [Atlassian]
        7. project_roles.png
          29 kB
          Justin Alex [Atlassian]

              Unassigned Unassigned
              jalex Justin Alex [Atlassian] (Inactive)
              Votes:
              3 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: