Security situation. New User can see all projects having no role or access to any of them.

Andrej V. April 22, 2015

We create a new user in local JIRA system but for some reason this user see all projects and boards (with no issues)

User have only one group "jira-users" and have no roles in any project. In Permission Sheme" jira-users" have no permissions exept JIRA access only.

Access to projects we managing by roles assigning to users.

In 2014 there in no such problem and now we can't find what is changed..

Any suggestions how can we fix such thing?

Thanks in advance.

1 answer

1 accepted

1 vote
Answer accepted
Rahul Aich [Nagra]
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
April 22, 2015

Check what is defined in the browse-projects permission. Do you have any project role or group defined in it.

If yes, check if the user is part of that role or group.

Only way a user can get access to a project is by having the browse issue permission.

Why he is not able to view issues is a different issue and reasons can be many,buts thats not the issue here.

Rahul

Andrej V. April 22, 2015

Thanks.

I checked what is defined in the browse-projects permission.

We have an permission that allows browse projects by "Author".

So Any user that can create an issues can see any project no metter what permissions are set in project for group or role or user.

 

Suggest an answer

Log in or Sign up to answer