An issue security scheme is created for my project. In the project there are project roles: Project role 1 and Project role 2.
The following security levels are created in the issue security scheme:
Level 1 - Project role 1
Level 2 - Project role 2
A user "User 1" has project role "Project role 1" , a user "User 2" has project role "Project role 2".
User 1 has created an issue (TEST-1), a security level of TEST-1 is set to Level 1. If User 2 tries to view TEST-1 using url link to TEST-1, he cant open it. That is correct.
But if User 2 selects TEST-1 using jql search he can see the issue in the result list. He still can not open this issue, but if he knows field names he can specify columns and get the data!
Is this a bug? Or such behaviour of the issue security is normal?