Does role permissions work after assigning a LDAP group to a project role?

Hao Zhang July 12, 2016

It seems like role permissions are not applied or not working properly in project roles. If I go to 'Roles' in 'Project administration' and add existing LDAP groups to "Users" and "Developers" role, the permissions will not be fully applied.

My case: I assigned existing LDAP groups to "Users" and "Developers" roles, and the person from this group could see my tickets (the tickets in the project), but couldn't comment them or add a new one. He was able to change the status of the ticket (task). This is not the correct permission.
When I put the specific single user to "Users" and "Developers" roles, he was able to do comment and update tickets and create a new one. This is what it should be.
It seems like groups are somehow proceed not correctly.

So my question is: Does role permissions work after assigning a LDAP group to a project role?

1 answer

0 votes
Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
July 13, 2016

Yes, they do work.  JIRA doesn't care what directory a group comes from. 

My best guess is that you've put the user in the right LDAP groups, but the directory has not yet been synchronised, so JIRA does not yet know that they are in the group.  Using JIRA's internal group browser, see if you can see the users in there.  And maybe go to user directories -> ldap -> synchronise (or just leave it a while - most systems will sync at least hourly)

Hao Zhang July 13, 2016

I went to "User management" -> "User Directories" and found 2 user directories.

The one on the top is the LDAP authentication, and the one below it is "JIRA Internal Directory".

 But I didn't find any button or link with the word "synchronise" or "sync".

 

Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
July 14, 2016

Oh, hang on, do you mean you are only using LDAP for authorisation?

If that's the case, then LDAP is utterly irrelevant to the groups - JIRA is using internal groups only and putting people into LDAP groups is going to have no effect.

Hao Zhang July 14, 2016

Almost all the users (except Jira internal users such as admin) are using LDAP authentication.

Does the role permissions work on LDAP groups in this case?

 

Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
July 14, 2016

I don't know, because you have not told us what "using LDAP authentication" means.

Are you using LDAP for just authentication?  (the missing option to synchronise implies that you are).  OR, are you using it as a full directory, with users and groups?

It might be easier for you to take a screenshot of Admin -> User directories and show us the full list of directories you have set up.  That would clarify it better than my words

 

Hao Zhang July 14, 2016

4.png

Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
July 14, 2016

Ok, great, that is exactly what I thought.

Your LDAP directory is only being used for authentication.  It gives JIRA a list of valid users, and when they try to log in, it checks their password against their LDAP one.

It does NOT provide groups or group memberships to JIRA, it's just authentication.  It's irrelevant what LDAP groups a user is in, as those groups have nothing to do with JIRA.

Hao Zhang January 9, 2017

OK I see. Thanks for the answer.

Suggest an answer

Log in or Sign up to answer