Hi all, and Happy New Year.
Hoping someone can help with the following query. Essentially my aim is to create security-level access that only allows access to a ticket if the user is a participant in that ticket. Below I've gone into a bit more detail about the scenario types.
Overall Scenario:
Users can ONLY access tickets where they are a participant.
Background: The user has access to the project
Project > People
Project > Permissions
Scenario: I can access the ticket
Given I am the Reporter, Assignee or Watcher of a ticket
OR I belong to the it-dev group project role?
Then I am a participant in that ticket
And I can access that ticket
(Project roles and permissions determine what user can do in that ticket)
Scenario: I can NOT access the ticket
What if a non-participant is tagged in a comment?
Scenario: I can be tagged in comments
Scenario: I can NOT be tagged in comments