Uploaded image for project: 'Jira Service Management Cloud'
  1. Jira Service Management Cloud
  2. JSDCLOUD-8990

Permission scheme allows unlicensed users to add internal comments to issues

    XMLWordPrintable

Details

    Description

      Issue Summary

      Adding the options 'Reporter' or 'Service Desk Customers' (project role) or Service Desk Team ( Project Role )to the Add Comments permission in the permissions scheme causes customer replies to service desk notifications to be added as internal comments even if the project mail handler is turned off.

      Steps to Reproduce

      1. Add 'Reporter' or 'Service Desk Customers' (project role) or Service Desk Team ( Project Role ) to the Add Comments permission in the permissions scheme associated with your project;
      2. Disable email requests;
      3. Create a request on behalf of a customer (make sure to select a valid request type so your customer will receive notifications);
      4. Ask your customer to reply to the 'Request created' notification.

      Expected Results

      The reply won't be added as a comment since the project mail handler is disabled.

      Actual Results

      The reply is processed by the Default Cloud Mail Server (Jira settings > System > Incoming mail) and is added to the issue as an internal comment.

      Workaround

      Add Service desk customer - portal access to the permission scheme and make sure that the permission is not granted to 'Reporter' or 'Service Desk Customers.
      Currently there is no known workaround for this behavior. A workaround will be added here when available

      Attachments

        Issue Links

          Activity

            People

              mgrauel@atlassian.com mo
              vromero Victor Romero
              Votes:
              20 Vote for this issue
              Watchers:
              34 Start watching this issue

              Dates

                Created:
                Updated: