Why epic creation is possible even if user doesn't have the permission to create issues?

Julia Schneider July 21, 2021

In our company managed project I created a permission scheme where only admins, project leader and users with a specific role for this project can create issues.

Now if a user who doesn't belong to any of these roles is not able to create a story, task or subtask but still he can create epics. Why? And how can I prevent a user from creating epics in a project he doesn't belong to?

Thanks in advance for your support.

2 answers

2 accepted

1 vote
Answer accepted
Airbus Driver
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
July 22, 2021

Create a dedicated workflow for your EPIC-type issue and ensure that a validator is configured in the 'Create' transition. Choose the Permission Validator and then choose the Administer Projects permission.

Julia Schneider July 22, 2021

Thank you Airbus Driver. As you said I created a new workflow for the EPIC with the permission Validator. But still epic can be created going from the backlog view as shown in the picture of the above reply.

Airbus Driver
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
July 23, 2021

I tried to recreate this issue in my environment. This is what I did;

  • Created a project and set the 'Create Issues' permission to user_A and user_B only
  • Created a board with a filter that takes issues from two different projects (existing and another project)
    • In existing project, user_C does NOT have 'Create issues' permission
    • In another project, user_C has 'Create issues' permission
  • I logged in as user_C, went to the board backlog and I was able to create an Epic. HOWEVER, when user_C clicks on 'Create Epic', the current project was not listed which means that they cannot create an Epic in the current project but they can in another project where they have the 'Create issues' permission.

 

Looks like the ONLY way to stop the user from creating ANY epics from a Scrum backlog is to remove the 'Create Issues' permission from ALL projects. I wonder if there is a better alternative.

0 votes
Answer accepted
Ashu Tyagi
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
July 22, 2021

@Julia Schneider  Can you check if EPIC has same workflow as other issuetypes or uses a different workflow,

If EPIC has different workflow then please check the validator in Create transition of it's workflow  and see which permission it allows

Julia Schneider July 22, 2021

EPIC has the same workflow as the other issues.image.png

and can't be created in the Roadmap but in the Backlog viewimage.png

Suggest an answer

Log in or Sign up to answer