Hi,
I was recently came across an issue in which a user was able to see a Project in Jira which in they didn't need to have access to.
I primarily use Permission Schemes for projects created in JIRA to set and allow User Groups functionality within specific Jira projects. The user in question was not in any browse or create groups within the permission scheme for the project in question but was still able to view. After some digging around I eventually found that a user group had been added to the "People" section within Project settings which was allowing the specific user to browse and create in said project, by a previous administrator.
I've done some looking into both "Permission Schemes" and "People" after coming across this and can't really seem to find any difference between the two. Is there a best practice in which people use permission schemes and people to create specific project permissions or do the two just give similar functionality. Is it more for ease of managing within People with it being between Administrators or developers. Rather than a more granular level within a permission scheme?
As mentioned above, I am more accustomed to using permission schemes and associating these to specific projects but a previous Admin seems to have used the "People" setting on some projects and not others and I cannot think or find online any benefits to one over the other.
Apologies if there are open discussions or pages discussing this topic but some searching around the topic haven't really returned any best practice or over sweeping answers.
Additionally it may be that I was searching for "People" rather than "Project Roles", and that after some additional research into this after posting the question is that, project roles can be managed by project administrators rather than JIRA Administrators, but if this is the case, is it then easier to have a global permission scheme for every project within a Jira instance which is set to Jira Administrators only, and then project roles used within each project and managed by project admins. Rather than having a specific permission scheme for every project created? It just seems to be duplication unless permission schemes aren't used along side it.
Any help with this would be greatly appreciated.
Steven