I have set the Browse Project permission to the project role Users, but a user that is only in that project role can view in the issue navigator also the issues that has set a security role that should deny the view permission to him. If he click on these issues he get a permission violation error page.
Is this correct? In my opinion he should not view these issues in the issue navigator!