Hi All, According to the below doc, I have granted the Browse Project permission to the Client Project role and i am adding the client to the project role of only those projects which are associated to a particular customer. But somehow, When i am adding a user who is only added to jira-software-user group, i am able to view all the project name. Though i cannot see the data on those projects but it is still a security issue. Is there something which i am missing? Did Atlassian change something on the recent cloud versions?
https://confluence.atlassian.com/jirakb/how-to-restrict-project-access-to-different-isolated-user-groups-290750862.html
Hi Vineet,
default project permission scheme in the Cloud allows to all of your users browse the projects.
Go to Project settings - permissions - and edit permissions of your permission scheme or switch to another scheme.
I recommend set permissions for "Project role", not for "Application access", but this deppends on character of your projects :-)
"Application access (Any logged in user)" means all of your jira users.
Examples...
Hidden project permission settings:
Open project permission settings:
Hi Lukas, Thanks for your response, Removing the "Any logged in user" from the Browse projects permission is the first thing which i did, And i have used project role instead of groups and even i have not added the test user to any of the projects roles, I can see all the projects from the user's login.
It looks like you're new here. Sign in or register to get started.