Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Can jira-administrators access project details via REST API without "Browse Project" permission?

Umut Emre Önder
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 8, 2024

The documentation states that the REST API "/rest/api/2/project/{projectIdOrKey}" requires the "Browse Projects" permission and mentions that a 404 error is returned when the user lacks permission to view it.

However, I've observed that if the user is a Jira administrator, the API returns a 200 status code with the correct response body, even if they do not have permission to browse the project. Is this behavior intended?

1 answer

0 votes
Mani Chaitanya
Contributor
August 8, 2024

Strange!!!  I know if it's getting authenticated with service account  instead of human account then permission might be a concern

Suggest an answer

Log in or Sign up to answer