Access the REST API as a specific user rather than an overall system

So, right now, I am accessing the JIRA Rest API through my rails app.

If a user of my app wants change the "status" of an issue, I check to see if their associated JIRA user account is a member of groups with permissions to change that issue's status. 

For instance, if the JIRA username "Beckah" is part of the "jira-administrators" groups, they can change an issue's status from "In Progress" to "Complete".

My question is, is there a way to enforce these kinds of rules through Jira's rest API? In plain English, with a Rest PUT request, "User Beckah wants to move Issue NEM-11 to Complete" and see if it JIRA responds with an error or success based on Beckah's permissions to update that issue. 

Let me know if that makes any sense or if more details are needed.

1 answer

0 vote
Boris Berenberg Community Champion Aug 01, 2017

You need to use oAuth instead of basic auth in your rails app. You also need to support user impersination.

Is there a specific tutorial on jira oauth user impersonation? can't find anything.

Suggest an answer

Log in or Sign up to answer
How to earn badges on the Atlassian Community

How to earn badges on the Atlassian Community

Badges are a great way to show off community activity, whether you’re a newbie or a Champion.

Learn more
Community showcase
Published Thursday in Agile

How Davin Studer gets Confluence to do everything he wants it to do...except dishes

  @Davin Studer holds many interests, including but not limited to health tech and Star Trek. Read on to discover more about Davin, from his favorite Confluence macros to his favorite lit...

201 views 1 9
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you