Uploaded image for project: 'Jira Service Management Data Center'
  1. Jira Service Management Data Center
  2. JSDSERVER-3507

You do not have permission to view this attachment

    XMLWordPrintable

Details

    Description

      Summary:

      If a User whether it is an agent or customer sending an email with an existing issue key on its subject (or have an intention to comment on an existing ticket), if they don't have the permission to view the ticket due to security level, this misleading "You do not have permission to view this attachment" will shown on the JSD Email Settings "Processing Log"

      Steps to reproduce:

      1. Create a Dummy Service Desk project and set the Mail Channel
      2. Create a new Issue Security Scheme and set the Security Level as simple as:
        1. Name: Level 1
        2. Reporter
        3. Current Assignee
        4. agent1
      3. Assign the scheme to the dummy project.
      4. As a customer create a ticket
      5. Back as an agent1, set the security level of that ticket to "Level 1"
      6. As an agent2 that have the permission to access the project, prepare an email with the issue key as the subject.
      7. Comment on the mail body and attach a file.
      8. Send the Email

      Expected Result:

      • The email will be rejected as the agent2 does not have permission to access the ticket with a message "You do not have permission to view the ticket" on the "Processing Log"

      Actual Result:

      • The email is rejected with a message "You do not have permission to view this attachment" on the Processing log

      Notes:

      • Based on my test:
        • If there is no attachment, the comment is added even though that user not able to view it.
        • If there is an attachment, with the "You do not have permission to view this attachment" the attachment is still added while the comment is not.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              jrahmadiputra Julian (Inactive)
              Votes:
              31 Vote for this issue
              Watchers:
              21 Start watching this issue

              Dates

                Created:
                Updated:

                Backbone Issue Sync