Hello,
I would like to give admin rights to every user that uses my plugin. Is this possible? And if yes how can I do that?
JiraAuthenticationContext jac; // ... get it from injection or something ApplicationUser userBefore = jac.getUser(); //current user ApplicationUser wannabeUser = // ... admin, if you want jac.setLoggedInUser(wannabeUser); try { //... do sensitive stuff here } finally { jac.setLoggedInUser(userBefore); }
Well, your plugin could add them to the administrators group, but I'd strongly recommend not doing this (as all of my Jira jobs in the last 9 years have started with "please clean up the mess made by having too many admins")
Could you explain what you are actually trying to achieve in this plugin? I really don't think you mean you want to give users admin rights, I suspect you're just trying to do something normally restricted to an admin?
Yes, your're right. I want to update the owner of a filter. Therefore I need to be administrator.
updateFilterOwner(JiraServiceContext serviceCtx, ApplicationUser user, SearchRequest request) Persists a <a href="https://developer.atlassian.com/static/javadoc/jira/6.2.7/reference/com/atlassian/jira/issue/search/SearchRequest.html" rel="nofollow noopener noreferrer">SearchRequest</a> to the database - only available to administrators.
updateFilterOwner(JiraServiceContext serviceCtx, ApplicationUser user, SearchRequest request)
<a href="https://developer.atlassian.com/static/javadoc/jira/6.2.7/reference/com/atlassian/jira/issue/search/SearchRequest.html" rel="nofollow noopener noreferrer">SearchRequest</a>
My plugin should change the fixVersion in a filter's query. And in order to change the filter you must be the owner. But everybody using the plugin should be able to change the filter. So I have to develop a workaround.
So my approach:
When normal user wants to update:
Would this be possible, or are there better approches?
That won't work - you need admin rights to update the admin group.
Updating the owner of a filter by any old user is probably not a good idea - if I've written a load of filters and used them in dashboards and reports, then I don't want other people arbitrarily taking my filters away and possibly breaking them for me.
The API has ways to override security if you're coding in a plugin, but it's been a while since I used them, and I can't remember them.
A quick cheat might be to have a dummy admin user and use that instead of the current user (although that chews up a licence seat, and is hard-coding so it's a bit ugly)
Please give some more advices:
- To create a dummy admin user, I again need to be administrator, or how can I do that?
In short, I find your solution (to offer admin rights each time) a bit cumbersome.
Thanks for your code sample.
One more question:
How do you initialize the wannabeUser, so that this user is an admin user? Can I do that in my plugin? Can I do that overall without being an administrator myself?
Can you please give a code sample of the Initialization?
UserManager umgr; // again, inject
ApplicationUser wannabeUser = umgr.getUserByKey("admin"); //well, put it in some config
Happy ?
It looks like you're new here. Sign in or register to get started.