Set Permissions for webwork1

Hi,

according to this example

http://jira-plugin-pack.googlecode.com/svn/trunk/jira-plugin-pack/src/atlassian-plugin.xml

i tried to make one of my webwork1-modules only available for admin-users.

<webwork1 key="myAdminWebwork" name="Administer user dashboards"
		class="java.lang.Object" roles-required="admin">
...
</webwork1>

Unfortunately the additional attribute "roles-required" had absolutly no effect. Also this webwork can be called even without a login. I tried several other approaches by using condition, but nothing works so far. In the Documentation I've only found ways to secure websections, plugins etc. but not how this is done for webworks.

Greetings Sebastian

2 answers

1 accepted

This widget could not be displayed.

As you said, conditions can be done only on web-sections, web-items etc thus preventing users from seeing the action. But they will still be able to access it directly.

You need to handle within the action class. Within the methods, check the permissions before doing anything and redirect to a permission error page if the permission is not there.

A typical example:

if (!permissionManager.hasPermission(Permissions.ADMINISTER, getLoggedInUser())) {
    return "securitybreach";
}

Hi Jobin,

thanks for your answer. I already used a construct like the one you posted, but i thought there must be a way to handle this in the atlassian-plugin.xml. Anyway, i'm fine with this :)

Greetings Sebastian

This widget could not be displayed.

What Jira version the additional attribute "roles-required" had absolutly no effect?

I'm trying in 5.0.7 and works fine.

usuario
sustantivo: usuario, consumidor, adicto, aprovechador

Suggest an answer

Log in or Sign up to answer
Atlassian Summit 2018

Meet the community IRL

Atlassian Summit is an excellent opportunity for in-person support, training, and networking.

Learn more
Community showcase
Posted Aug 06, 2018 in Jira Service Desk

A is for Activate: Share your top Jira Service Desk onboarding tips for new users!

Hi, everyone! Molly here from the Jira Service Desk Product Marketing Team :).  In the spirit of this month's  august-challenge, we're sourcing stories of Jira Service Desk activation fro...

573 views 25 15
Join discussion

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you