Uploaded image for project: 'Jira Service Management Cloud'
  1. Jira Service Management Cloud
  2. JSDCLOUD-8015

'Service Desk Customer - Portal Access' in Browse Project permission causes side bar to display search suggestions to users with no access to said suggestions

    XMLWordPrintable

Details

    Description

      Summary

      When the browse project permission of a project is set to include 'Service Desk Customer - Portal Access', currently users with JSW application access (but have no access to the project due to not being a JSD customer) , is able to see tickets, boards, projects and filters of the said project. They do not have access to the project in question when clicking on the boards and projects but they are still able to see the projects and issues from suggestions.

      Investigation Done

      Browse project permission set to include 'Service Desk Customer - Portal Access'

      No additional groups besides application access group for user

      User is still able to see the project (AT1) being suggested despite not having access to it.

      Steps to Replicate

      Refer to the investigation steps above.

      Expected Results

      No projects, dashboard, filters or tickets should be return as suggestion

      Current Results

      Projects with Browse Project permission that includes 'Service Desk Customer - Portal Access' will return itself, tickets and dashboards under it as suggestion despite the user having no access to it.

      Note : Can also potentially be due to side bar result caching with the creation of CONFCLOUD-65887 but have no way of verifying on our end.

      Attachments

        1. 1D0-437.pdf
          518 kB
          examdumps
        2. 1Y0-240.pdf
          592 kB
          examdumps
        3. 1Y0-311.pdf
          532 kB
          courtneymichael876
        4. 1Z0-320.pdf
          440 kB
          examdumps
        5. 1Z0-348.pdf
          457 kB
          examdumps
        6. 1Z0-477.pdf
          463 kB
          examdumps
        7. 1Z0-962.pdf
          437 kB
          examdumps
        8. 1Z0-970.pdf
          435 kB
          examdumps
        9. 1Z0-975.pdf
          511 kB
          examdumps
        10. 1Z0-976.pdf
          436 kB
          examdumps
        11. 200-150.pdf
          691 kB
          examdumps
        12. 200-601.pdf
          621 kB
          examdumps
        13. 210-060.pdf
          439 kB
          examdumps
        14. 250-430.pdf
          454 kB
          examdumps
        15. 2V0-751.pdf
          1.05 MB
          examdumps
        16. 300-160.pdf
          443 kB
          examdumps
        17. 3V0-622.pdf
          1.56 MB
          examdumps
        18. 9A0-411.pdf
          546 kB
          examdumps
        19. 9A0-412.pdf
          1.04 MB
          examdumps
        20. access.mp4
          3.25 MB
          Vincent Chin
        21. access1.mp4
          3.15 MB
          Vincent Chin
        22. access2.mp4
          3.97 MB
          Vincent Chin
        23. AICP.pdf
          1.14 MB
          examdumps
        24. C_HANATEC_14.pdf
          459 kB
          examdumps
        25. C_HYMC_1802.pdf
          520 kB
          examdumps
        26. C5050-384.pdf
          1.05 MB
          anthony
        27. CLTD.pdf
          1.01 MB
          examdumps
        28. he's an admin.png
          34 kB
          Albert
        29. HPE6-A44.pdf
          1.64 MB
          examdumps
        30. HPE6-A45.pdf
          590 kB
          examdumps
        31. JN0-361.pdf
          528 kB
          examdumps
        32. JN0-420.pdf
          1.46 MB
          examdumps
        33. JN0-647.pdf
          971 kB
          examdumps
        34. MS-500.pdf
          655 kB
          examdumps
        35. NCM_20002021610.pdf
          1.01 MB
          examdumps
        36. PEGAPCSA80V1_2019.pdf
          543 kB
          examdumps
        37. screenshot-1.png
          18 kB
          Vincent Chin
        38. screenshot-2.png
          53 kB
          Vincent Chin
        39. Screen Shot 2019-04-04 at 4.24.19 pm.png
          83 kB
          Karol
        40. Screen Shot 2019-04-04 at 4.25.43 pm.png
          175 kB
          Karol
        41. Screen Shot 2019-04-04 at 4.27.33 pm.png
          137 kB
          Karol
        42. Screen Shot 2019-04-04 at 4.29.25 pm.png
          62 kB
          Karol
        43. Screen Shot 2019-04-04 at 4.29.32 pm.png
          54 kB
          Karol
        44. Screen Shot 2019-04-04 at 4.33.12 pm.png
          44 kB
          Karol
        45. Screen Shot 2019-04-04 at 4.34.16 pm.png
          55 kB
          Karol
        46. Screen Shot 2019-04-04 at 4.36.07 pm.png
          95 kB
          Karol
        47. Screen Shot 2019-05-13 at 11.35.51 am.png
          115 kB
          Karol
        48. Screen Shot 2019-05-13 at 11.36.17 am.png
          39 kB
          Karol
        49. Screen Shot 2019-05-13 at 11.43.21 am.png
          158 kB
          Karol
        50. Screen Shot 2019-05-13 at 4.38.22 pm.png
          170 kB
          Karol
        51. screenshot-3.png
          12 kB
          Vincent Chin
        52. screenshot-4.png
          60 kB
          Vincent Chin
        53. screenshot-5.png
          60 kB
          Vincent Chin
        54. screenshot-6.png
          84 kB
          Vincent Chin
        55. screenshot-7.png
          92 kB
          Vincent Chin
        56. software-has-admin.png
          59 kB
          Albert
        57. Untitled.png
          55 kB
          Vincent Chin

        Issue Links

          Activity

            People

              ktarasiuk@atlassian.com Karol
              vchin Vincent Chin (Inactive)
              Votes:
              1 Vote for this issue
              Watchers:
              8 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: