Uploaded image for project: 'Jira Software Server and Data Center'
  1. Jira Software Server and Data Center
  2. JSWSERVER-6037

Restrict editing of the Sprint CF to users with Schedule permission for that issue

    XMLWordPrintable

Details

    • 0
    • 3
    • We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

    Description

      This is something I found randomly and I guess it makes sense for us to check. I tried this on a clean installation and reproduced many times in different ways. In a nutshell, I think the shortest path to demonstrate is the following:

      1. Let us say I have a project named ABC and a Rapid Board ABC Board containing issues from that project.
      2. I also have two users:
        1. charlie: All permissions on project ABC
        2. alpha: Only in jira-users, essentially only able to create issues in ABC (user has been added specifically in this example but it would work for him anyway):

      3. Project roles in ABC are like the following:
      4. charlie creates ABC-1:
      5. Then charlie adds ABC-1 to Sprint 1 (just created by him, also):
      6. The sprint id for that sprint is 1 (the address bar is from the sprint report):
      7. The Sprint field is also visible on all screens:
      8. Now user alpha tries to create an issue in JIRA. Remember that he cannot even browse project ABC but he can edit the Sprint Field and add the sprint id (1, in this case):
      9. ... so when he tries to view ABC-2 he cannot:
      10. However, ABC-2 has been added to the sprint:

      Should this be possible? Am I missing something, perhaps?

      Attachments

        1. 10-issueadded.png
          10-issueadded.png
          57 kB
        2. 1-alphagroups.png
          1-alphagroups.png
          29 kB
        3. 2-createissues.png
          2-createissues.png
          40 kB
        4. 3-people.png
          3-people.png
          16 kB
        5. 4-create.png
          4-create.png
          30 kB
        6. 5-plan.png
          5-plan.png
          30 kB
        7. 6-sprintId.png
          6-sprintId.png
          16 kB
        8. 7-sprintfield.png
          7-sprintfield.png
          31 kB
        9. 8-alphacreatesissue.png
          8-alphacreatesissue.png
          67 kB
        10. 9-permissionviolation.png
          9-permissionviolation.png
          24 kB

        Issue Links

          Activity

            People

              Unassigned Unassigned
              ttzidamis Theodore Tzidamis (Inactive)
              Votes:
              9 Vote for this issue
              Watchers:
              14 Start watching this issue

              Dates

                Created:
                Updated: