-
Type:
Bug
-
Resolution: Timed out
-
Priority:
Low
-
None
-
Affects Version/s: 6.4.5
-
Component/s: Project Administration - Permissions
-
6.04
-
Severity 3 - Minor
-
Summary
Users are able to create/comment issues via email without group membership if they are added directly to the project's permission.
User shouldn't be able to do that since he can't access the application itself.
Same applies to JIRA's notifications.
Steps to Reproduce
- Remove user from all groups
- Add user directly to the project's "Browse Projects" and "Create Issues" permissions
- Send an email to JIRA form the user/trigger notification to user from JIRA
Expected Results
User doesn't create issues/receive notification since he can't log into JIRA
Actual Results
User successfully creates issues and receives notifications from JIRA