Hi All, According to the below doc, I have granted the Browse Project permission to the Client Project role and i am adding the client to the project role of only those projects which are associated to a particular customer. But somehow, When i am adding a user who is only added to jira-software-user group, i am able to view all the project name. Though i cannot see the data on those projects but it is still a security issue. Is there something which i am missing? Did Atlassian change something on the recent cloud versions?
Hi Vineet,
default project permission scheme in the Cloud allows to all of your users browse the projects.
Go to Project settings - permissions - and edit permissions of your permission scheme or switch to another scheme.
I recommend set permissions for "Project role", not for "Application access", but this deppends on character of your projects :-)
"Application access (Any logged in user)" means all of your jira users.
Examples...
Hidden project permission settings:
Open project permission settings:
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Lukas, Thanks for your response, Removing the "Any logged in user" from the Browse projects permission is the first thing which i did, And i have used project role instead of groups and even i have not added the test user to any of the projects roles, I can see all the projects from the user's login.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Atlassian Government Cloud has achieved FedRAMP Authorization at the Moderate level! Join our webinar to learn how you can accelerate mission success and move work forward faster in cloud, all while ensuring your critical data is secure.
Register NowOnline forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.