We have got two Jira Data Center installations, one as productive instance and one as instance to test.
In the test instance today I detected a strange behaviour:
A new user without any assignments to roles in projects or to groups could see rack-wheel at the top right edge and select "Projects". So he could change workflows of any project and assign himself as administrator to any project. Maybe he could do much more things I don't want him to do.
This shocked me, and I had a look at the productive instance.
I created a new user without any permissons or groups, like the user in the test instance.
There the user couldn't see the rack-wheel and couldn't administrate anything.
Though I was relieved, I still ask myself why the two instances behave different in this point. The global permissions are identically in both instances. Only the group "jira-administrators" may administrate Jira.
We want to develop a permission concept and test our ideas in the test instance.
But therefore we must be sure that the behaviour of the two instances is identical.
Does anybody have an idea what we can do?