At present, anyone - even people not logged in - are able to transition an issue.
Yes, it's a bit of a flaw that is fixed by Atlassian adding a default "must have a generic transition-issue permission" explicit in the permission schemes - but you'll need JIRA 6.2 or above, if I remember right.
Otherwise, no, there's no protection, and anyone can use a transition unless you put at least one "condition" on it. I'm afraid you need to edit all your workflows and add conditions (even if it's just "is a JIRA user", I'd recommend putting a condition on every transition every time)
Thank you, I was afraid of that. Stunning oversight on Atlassian's part.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Yup, been a bit of a pain to remember to put conditions on every new transition for the last <mumble> years.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.