-
Suggestion
-
Resolution: Duplicate
-
None
-
None
Users that have the "Administer Jira" Project permissions have the ability to add new status even if they do not have the "Administer Jira" global permission. They can create the new statuses by going to the board settings and using the "Add new Status" button from there. This effectively bypasses the permissions that would prevent them from creating a new status in the first place.
This can represent a small security issue in that it does not allow the site-admins enough granularity to prevent project owners from creating a great many different statuses in the global space.
I would like to propose that the permissions be made more clear and more granular such that you can prevent users from adding new statuses without having proper permissions, but can otherwise manage the project settings.
- duplicates
-
JSWCLOUD-15276 Simplified Workflow: add option to disable the creation of new statuses
- Gathering Interest
- is related to
-
JSWCLOUD-8845 Ability to define permission to create status via Simplified Workflow
- Closed