After upgrading JIRA from Version 4.3.4 to JIRA 5.1.1 we have noticed, that we have a problem with the Issue Security Scheme. We noticed it when filters didn't show any issues although the affected users do have viewer and worker rights on the project and Issue Security is set properly by a Group Custom Field Value. It worked smoothly before the upgrade and we didn't change any configuration setting afterwards.
We already raised an issue: https://jira.atlassian.com/browse/JRA-29196 and got the answer if we need a bugfix INSTANTLY, we need to open an issue here.
More detailed bug description:
The security level of the issues is configurerd with a specific Issue Security Scheme. The Customer Security Level is set with a Group Custom Field Value. In our case we use the content of a field named Bank Unit. Bank Unit is a Custom Field of type Select List.
All values of that select list are group names too (e.g. Value of Bank Unit: Bank xy and group name of the group to which the user belongs: Bank xy).
Issue security works fine with direct URLs. A user can access issues, when he is in the group mentioned in the field Bank Unit and he is blocked, when he is not in that group.
All filters/queries return zero – even if we use a very simple search criteria like project = Project A