Hi everyone.
I am using Jira Software v.9.0.0. I set up several roles, the scheme of access rights for projects regarding roles - I removed any access for any groups, for any logged in user, etc., all rights are set only for project roles.
After all, I noticed the following problem - anyone who is a member of the jira-software-users group can view ALL existing projects and change the roles assigned to users in them. That is, anyone can go to an existing project (even if he does not have a role in this project) and add the project administrator role to himself, which makes the configured access rights schemes useless.
After searching, it seemed to me that the problem was in the jira-software-users group. I was advised to make a new group and in the Applications settings add access to Jira Software to it so that users can log in. Then I created a jira-developers group, gave it access to Jira-Software. As a result, this group began to have the same disadvantages as jira-software-users, that is, all its users see all projects and can change project roles in them.
So there are two problems:
1) users of the jira-software-users group see all projects (even if they are not assigned a role in this project);
2) any user in the project can change the role scheme (add new users and give them roles, change their roles, etc.).
It would also be nice to set it up so that a certain user group or role can see only the issues of the project, and not the entire project with its settings. Maybe I didn’t understand something and the problem is not in the jira-software-users group.