The documentation states that the REST API "/rest/api/2/project/{projectIdOrKey}" requires the "Browse Projects" permission and mentions that a 404 error is returned when the user lacks permission to view it.
However, I've observed that if the user is a Jira administrator, the API returns a 200 status code with the correct response body, even if they do not have permission to browse the project. Is this behavior intended?
Strange!!! I know if it's getting authenticated with service account instead of human account then permission might be a concern
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.