Uploaded image for project: 'Jira Software Data Center'
  1. Jira Software Data Center
  2. JSWSERVER-24779

BUG: Manage shared team is allowed even if "Shared Team Management" permission is not granted

      Expected Behavior

      Only users with "Shared Team Management" are able to edit a shared team, or share a presently private team.

      Actual Behavior

      Any user with access to a plan in which any team is added can modify that team - regardless of it being shared or private - or share a private team.

      Steps to Reproduce

      1. Create any team and add it to a plan accessible by any user;
      2. Access the plan as a user without "Shared Team Management" permission;

      Workaround

      There is no known workaround at this time.

          Form Name

            [JSWSERVER-24779] BUG: Manage shared team is allowed even if "Shared Team Management" permission is not granted

            Dear all,
            I would like to inform you that this issue in the project JPOSERVER is being migrated to the new project JSWSERVER. Your votes and comments will remain unchanged.
            Our team at Atlassian will continue to monitor this issue for further updates, so please feel free to share your thoughts or feedback in the comments.
            Sincerely,
            Aakrity Tibrewal
            Jira DC

            Aakrity Tibrewal added a comment - Dear all, I would like to inform you that this issue in the project JPOSERVER is being migrated to the new project JSWSERVER. Your votes and comments will remain unchanged. Our team at Atlassian will continue to monitor this issue for further updates, so please feel free to share your thoughts or feedback in the comments. Sincerely, Aakrity Tibrewal Jira DC

            Matthias Krauss added a comment - - edited

            Hello @qfeyaerts

            is there any advice how users should proceed, now after you closed this issue?

            On the one hand we are even happy that it won't be changed, as this bug was kind of the only way to use Teams in Jira (not Portfolio) without giving thousands of users the shared team mgmt persmission (which cannot be done as that admin interface is rather rudimentary, everybody could change delete teams of others without notice)

            BR

            Matthias Krauss added a comment - - edited Hello @qfeyaerts is there any advice how users should proceed, now after you closed this issue? On the one hand we are even happy that it won't be changed, as this bug was kind of the only way to use Teams in Jira (not Portfolio) without giving thousands of users the shared team mgmt persmission (which cannot be done as that admin interface is rather rudimentary, everybody could change delete teams of others without notice) BR

            Markus Dieterle added a comment - - edited

            Exactly the same Issue here v 2.10.0

            Portfolio Users also cannot be reduced due to this missing function: https://jira.atlassian.com/browse/JPOSERVER-1681

            It is also not possible to unshare the teams, I would have to delete them : (https://jira.atlassian.com/browse/JPOSERVER-1544 ).

             

             

            Markus Dieterle added a comment - - edited Exactly the same Issue here v 2.10.0 Portfolio Users also cannot be reduced due to this missing function: https://jira.atlassian.com/browse/JPOSERVER-1681 It is also not possible to unshare the teams, I would have to delete them : ( https://jira.atlassian.com/browse/JPOSERVER-1544  ).    

            REST endpoint responsible for sharing portfolio team is not limited to Jira administrators or users with 'Shared Team Management' permission.

            Every Jira user is able to send POST request to: /rest/teams/1.0/teams/{team_id}/setShared and share any team !

            Eryk Leniart added a comment - REST endpoint responsible for sharing portfolio team is not limited to Jira administrators or users with 'Shared Team Management' permission. Every Jira user is able to send POST request to: /rest/teams/1.0/teams/{team_id}/setShared and share any team !

              a3bccef2360e Sara Hekmat
              joanna.maciag664753585 joanna.maciag664753585
              Affected customers:
              7 This affects my team
              Watchers:
              15 Start watching this issue

                Created:
                Updated: