Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-29840

User Picker field affecting the Browser Project permission

    XMLWordPrintable

Details

    Description

      Custom field type 'Multi User Picker' will affect the Browser Project Permission, which users does not have the browser project permission(does not belong to any groups/project role related) will be able to view the project when add the custom filed into the 'browser project'.

      To reproduce the problem by using the following steps:

      1. Create a custom field by using the 'Multi User Picker' for all issue types and for project 'testing':
      2. Add the custom field to the 'Browse Projects' permission in project 'testing'.
      3. Create TWO users who does not belong to the browse projects permission users, in this testing case, they must not belong to 'Project Role (Administrators)', let's say 'amanda' and 'user'
      4. Create a issue 'mytest' and add user 'user' in the custom field.
      5. Log in as 'amanda'. you will be able to view the project 'testing', but not able to view any issues in this project.
      6. Log in as 'user', you will be able to view the project 'testing' and the issue 'mytest'
      7. Delete the custom field from browse projects, both 'amanda' and 'user' will not be able to view the project 'testing' as expected.

      Attachments

        1. st1.JPG
          st1.JPG
          36 kB
        2. st2.JPG
          st2.JPG
          101 kB
        3. st3.JPG
          st3.JPG
          29 kB

        Issue Links

          Activity

            People

              Unassigned Unassigned
              amwei AmandaA
              Votes:
              33 Vote for this issue
              Watchers:
              28 Start watching this issue

              Dates

                Created:
                Updated: