-
Bug
-
Resolution: Fixed
-
High
-
20
-
Minor
-
9
-
-
Issue Summary
Currently, if a JSM Service Desk project gets deleted while it has a link to a Confluence KB space in place, with the permission of "Who can view" it for the Knowledge base in the Project Settings set to "All logged-in users", this deletion does not revoke that permission and consequently all users can still access and see the Knowledge base space in Confluence Cloud, even if that user hasn't been granted permission within that space.
Steps to Reproduce
- Make sure your site has Confluence Cloud and Jira Service Management
- Create a Service Desk project in JSM
- Add a Knowledge base space to that project and make sure the permission of "Who can view" it in the Project Settings is set to "All logged-in users"
- Logged in as a user with no permissions within that Confluence space, access it and confirm that you're able to see it
- Now go to the SD project in JSM and send it to trash
- Return to the KB space logged in as a user with no permissions there and confirm that you can still see the space
Note: The issue also happens if the "JSM users" global permission is toggled off, but the permission wasn't changed to Only Confluence users first in the Project Settings for the Knowledge base.
Expected Results
Due to the user not having permission to see that space, and considering that the JSM project has been deleted, the integration should be removed. This will prevent the user without permissions from being able to view the content of that space.
Actual Results
Even though the user does not have permission to view that space, and even if the JSM project has been deleted, the integration is not removed. This allows users without permissions to continue seeing the content of that space.
Workaround
Usually, there's a banner on the Space Permissions page indicating that this Service Desk (JSM) + KB integration was in place, and in that message, there's a button where the admins can click to disable it.
In case that banner isn't available in your site, please reach out to the Support team so that we can help you with finding the ID of that permission in the site's database to proceed with modifying that using Confluence REST API.
- is related to
-
CONFCLOUD-75569 Remove JSM access automatically if the Space is unlinked from a JSM project
- Gathering Interest
- relates to
-
CONFCLOUD-75783 Restore space permissions to limited to users with a Confluence license after Space is unlinked from KB
- Gathering Interest
- mentioned in
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...