Hi,
we have several projects on our JIRA Software installation with different teams working on them and restricted access to these projects.
I gave the modify reporter permission and the browse users permission to some users. They seem to be able to change the reporter to a user who does not have any permissions in this specific project.
Is that correct? I don't think, that should be possible
Hi Anne,
I just tested this in our server environment with the same result. If you have the permission to change the author, you can change it to someone who otherwise has no permission at all on the project.
I looked through the issues on jira.atlassian.com but could not find an issue for that. Maybe you want to raise it there for gathering interest.
You can always see in the issue history, who changed the author and who originally created the issue. But I agree, this can lead to some strange behaviours.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.