Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-33872

Don't show list people in the "add watcher" dialog that cannot watch the issue

    XMLWordPrintable

Details

    Description

      It is possible for the "Add Watcher" dialog on the view issue page to suggest a user that cannot watch the issue. The client will render an error saying the user cannot be added. JIRA should not show users that cannot be added.

      1. Restore JIRA QA data.
      2. Goto an issue XSS-21.
      3. Try and add "<script>alert(document.cookie)</script>" as watcher.
      4. (BUG) You will get an error saying that the user cannot see the issue.

      Attachments

        Activity

          People

            Unassigned Unassigned
            bbain bain
            Votes:
            2 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: