Hi,
we have several projects on our JIRA Software installation with different teams working on them and restricted access to these projects.
I gave the modify reporter permission and the browse users permission to some users. They seem to be able to change the reporter to a user who does not have any permissions in this specific project.
Is that correct? I don't think, that should be possible
Hi Anne,
I just tested this in our server environment with the same result. If you have the permission to change the author, you can change it to someone who otherwise has no permission at all on the project.
I looked through the issues on jira.atlassian.com but could not find an issue for that. Maybe you want to raise it there for gathering interest.
You can always see in the issue history, who changed the author and who originally created the issue. But I agree, this can lead to some strange behaviours.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.