Uploaded image for project: 'Jira Service Management Cloud'
  1. Jira Service Management Cloud
  2. JSDCLOUD-8015

'Service Desk Customer - Portal Access' in Browse Project permission causes side bar to display search suggestions to users with no access to said suggestions

    XMLWordPrintable

Details

    Description

      Summary

      When the browse project permission of a project is set to include 'Service Desk Customer - Portal Access', currently users with JSW application access (but have no access to the project due to not being a JSD customer) , is able to see tickets, boards, projects and filters of the said project. They do not have access to the project in question when clicking on the boards and projects but they are still able to see the projects and issues from suggestions.

      Investigation Done

      Browse project permission set to include 'Service Desk Customer - Portal Access'

      No additional groups besides application access group for user

      User is still able to see the project (AT1) being suggested despite not having access to it.

      Steps to Replicate

      Refer to the investigation steps above.

      Expected Results

      No projects, dashboard, filters or tickets should be return as suggestion

      Current Results

      Projects with Browse Project permission that includes 'Service Desk Customer - Portal Access' will return itself, tickets and dashboards under it as suggestion despite the user having no access to it.

      Note : Can also potentially be due to side bar result caching with the creation of CONFCLOUD-65887 but have no way of verifying on our end.

      Attachments

        1. Untitled.png
          55 kB
          Vincent Chin
        2. software-has-admin.png
          59 kB
          Albert
        3. screenshot-7.png
          92 kB
          Vincent Chin
        4. screenshot-6.png
          84 kB
          Vincent Chin
        5. screenshot-5.png
          60 kB
          Vincent Chin
        6. screenshot-4.png
          60 kB
          Vincent Chin
        7. screenshot-3.png
          12 kB
          Vincent Chin
        8. Screen Shot 2019-05-13 at 4.38.22 pm.png
          170 kB
          Karol
        9. Screen Shot 2019-05-13 at 11.43.21 am.png
          158 kB
          Karol
        10. Screen Shot 2019-05-13 at 11.36.17 am.png
          39 kB
          Karol
        11. Screen Shot 2019-05-13 at 11.35.51 am.png
          115 kB
          Karol
        12. Screen Shot 2019-04-04 at 4.36.07 pm.png
          95 kB
          Karol
        13. Screen Shot 2019-04-04 at 4.34.16 pm.png
          55 kB
          Karol
        14. Screen Shot 2019-04-04 at 4.33.12 pm.png
          44 kB
          Karol
        15. Screen Shot 2019-04-04 at 4.29.32 pm.png
          54 kB
          Karol
        16. Screen Shot 2019-04-04 at 4.29.25 pm.png
          62 kB
          Karol
        17. Screen Shot 2019-04-04 at 4.27.33 pm.png
          137 kB
          Karol
        18. Screen Shot 2019-04-04 at 4.25.43 pm.png
          175 kB
          Karol
        19. Screen Shot 2019-04-04 at 4.24.19 pm.png
          83 kB
          Karol
        20. screenshot-2.png
          53 kB
          Vincent Chin
        21. screenshot-1.png
          18 kB
          Vincent Chin
        22. PEGAPCSA80V1_2019.pdf
          543 kB
          examdumps
        23. NCM_20002021610.pdf
          1.01 MB
          examdumps
        24. MS-500.pdf
          655 kB
          examdumps
        25. JN0-647.pdf
          971 kB
          examdumps
        26. JN0-420.pdf
          1.46 MB
          examdumps
        27. JN0-361.pdf
          528 kB
          examdumps
        28. HPE6-A45.pdf
          590 kB
          examdumps
        29. HPE6-A44.pdf
          1.64 MB
          examdumps
        30. he's an admin.png
          34 kB
          Albert
        31. CLTD.pdf
          1.01 MB
          examdumps
        32. C5050-384.pdf
          1.05 MB
          anthony
        33. C_HYMC_1802.pdf
          520 kB
          examdumps
        34. C_HANATEC_14.pdf
          459 kB
          examdumps
        35. AICP.pdf
          1.14 MB
          examdumps
        36. access2.mp4
          3.97 MB
          Vincent Chin
        37. access1.mp4
          3.15 MB
          Vincent Chin
        38. access.mp4
          3.25 MB
          Vincent Chin
        39. 9A0-412.pdf
          1.04 MB
          examdumps
        40. 9A0-411.pdf
          546 kB
          examdumps
        41. 3V0-622.pdf
          1.56 MB
          examdumps
        42. 300-160.pdf
          443 kB
          examdumps
        43. 2V0-751.pdf
          1.05 MB
          examdumps
        44. 250-430.pdf
          454 kB
          examdumps
        45. 210-060.pdf
          439 kB
          examdumps
        46. 200-601.pdf
          621 kB
          examdumps
        47. 200-150.pdf
          691 kB
          examdumps
        48. 1Z0-976.pdf
          436 kB
          examdumps
        49. 1Z0-975.pdf
          511 kB
          examdumps
        50. 1Z0-970.pdf
          435 kB
          examdumps
        51. 1Z0-962.pdf
          437 kB
          examdumps
        52. 1Z0-477.pdf
          463 kB
          examdumps
        53. 1Z0-348.pdf
          457 kB
          examdumps
        54. 1Z0-320.pdf
          440 kB
          examdumps
        55. 1Y0-311.pdf
          532 kB
          courtneymichael876
        56. 1Y0-240.pdf
          592 kB
          examdumps
        57. 1D0-437.pdf
          518 kB
          examdumps

        Issue Links

          Activity

            People

              ktarasiuk@atlassian.com Karol
              vchin Vincent Chin (Inactive)
              Votes:
              1 Vote for this issue
              Watchers:
              8 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: