Hey guys,
I have a new use case where we have a new project that we have a new user group setup for. We want to then restrict users in that group from seeing anything in a different existing project. I was trying to set this up without having to completely redo my existing project roles/permissions. Does anyone know if a method to restrict access if they have been assigned to a particular group? We do have ScriptRunner
Hey @Tanya B.
In the first place, using groups in project permissions doesn't scale your Jira configuration. You should use project roles in your permission schemes that way, you can know which group can have access or not based on the permissions that has been defined. That way, it goes on a project basis.
Using Scriptrunner here is just overkill which I think proper project configuration that comes native actually does the trick.
I'm using groups into roles. In order to block one user in a group of about 2000 users would require me to either script something to block if they are in a different group or create a second group of 1999 to remove the blocked user. I would then need to manage all 3 groups and ensure users are properly updated between the groups. I was hoping to not have to manage the groups in this way, since it would just be inherent for human error.
Having 2K users in the same group and used across multiple project in roles is bound to cause some problem at a future date. One of the things you could do is revisit the group and structure it in a way that it can be easily managed. For example, removing one user from the group is easy enough, create another group with only that user and add to the project role of the other project. Why create another group to add 1999 users when the problem is only from 1 user?
This is a unique case related to security and regulatory requirements. I thought there might be a way to script this to try to block access if user is in a specific group. That would be much easier and more secure than trying to redesign all of our groups and then manual effort to ensure the user in the secure groups isn't in the other groups they shouldn't be in. If we can't script it I will look to redesign the roles/groups.
It looks like you're new here. Sign in or register to get started.