Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-29840

User Picker field affecting the Browser Project permission

XMLWordPrintable

      Custom field type 'Multi User Picker' will affect the Browser Project Permission, which users does not have the browser project permission(does not belong to any groups/project role related) will be able to view the project when add the custom filed into the 'browser project'.

      To reproduce the problem by using the following steps:

      1. Create a custom field by using the 'Multi User Picker' for all issue types and for project 'testing':
      2. Add the custom field to the 'Browse Projects' permission in project 'testing'.
      3. Create TWO users who does not belong to the browse projects permission users, in this testing case, they must not belong to 'Project Role (Administrators)', let's say 'amanda' and 'user'
      4. Create a issue 'mytest' and add user 'user' in the custom field.
      5. Log in as 'amanda'. you will be able to view the project 'testing', but not able to view any issues in this project.
      6. Log in as 'user', you will be able to view the project 'testing' and the issue 'mytest'
      7. Delete the custom field from browse projects, both 'amanda' and 'user' will not be able to view the project 'testing' as expected.

        1. st3.JPG
          st3.JPG
          29 kB
        2. st2.JPG
          st2.JPG
          101 kB
        3. st1.JPG
          st1.JPG
          36 kB

            Unassigned Unassigned
            amwei AmandaA
            Votes:
            33 Vote for this issue
            Watchers:
            29 Start watching this issue

              Created:
              Updated: