Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-61246

I can create issue links to projects for which I do not have Link Issues permissions

      NOTE: This bug report is for JIRA Server. Using JIRA Cloud? See the corresponding bug report.

      Summary

      Creating issue links to projects for which I do not have Link Issues permissions

      Steps to Reproduce

      1. Create 2 projects in JIRA: project A and project B
      2. Project A is using default permission scheme, where Link Issues permission is set to Any Logged In user
      3. Project B is using a modified permission scheme where no role has the permissions to Link Issues
      4. Find an Issue in Project A, and link it to any issue in project B

      Expected Results

      Either result would be expected here:

      • JIRA creates the link on issue A, which is allowed per the permissions above, but does not create a link on issue in project B.
      • Or JIRA warns user that a reciprocal link can't be created on Issue B due to permissions (either way when we look at Issue B, we should not see any links)

      Actual Results

      JIRA creates the link on both issues, despite project B's permission scheme that does not allow any user to link issues

      Notes

      Workaround

      none

      Original Description

      This happened in a single-server setup, I had two projects, Project A and Project B. My user only had the Link Issues permission in Project A.

      I then tried to create an issue link from an issue in Project A to one in Project B which worked fine. I expected the issue link operation to fail b/c I just created an issue link on an issue of a project where I don't have the Link Issues permission. That just feels like breaking the permission restrictions.

            [JRASERVER-61246] I can create issue links to projects for which I do not have Link Issues permissions

            SET Analytics Bot made changes -
            UIS Original: 2 New: 1
            SET Analytics Bot made changes -
            UIS Original: 1 New: 2
            Conny Postma made changes -
            Link New: This issue is related to JRASERVER-78044 [ JRASERVER-78044 ]
            SET Analytics Bot made changes -
            Support reference count Original: 7 New: 8
            Conny Postma made changes -
            Affects Version/s New: 9.12.7 [ 107310 ]
            Affects Version/s New: 9.17.2 [ 108792 ]
            Conny Postma made changes -
            Labels Original: affects-cloud affects-server New: affects-cloud affects-server data-center
            SET Analytics Bot made changes -
            UIS Original: 0 New: 1
            SET Analytics Bot made changes -
            UIS Original: 1 New: 0
            SET Analytics Bot made changes -
            UIS Original: 0 New: 1
            SET Analytics Bot made changes -
            Support reference count Original: 6 New: 7

              Unassigned Unassigned
              akavelar Albert Kavelar
              Affected customers:
              6 This affects my team
              Watchers:
              16 Start watching this issue

                Created:
                Updated: