Hi everyone.
I am using Jira Software v.9.0.0. I set up several roles, the scheme of access rights for projects regarding roles - I removed any access for any groups, for any logged in user, etc., all rights are set only for project roles.
After all, I noticed the following problem - anyone who is a member of the jira-software-users group can view ALL existing projects and change the roles assigned to users in them. That is, anyone can go to an existing project (even if he does not have a role in this project) and add the project administrator role to himself, which makes the configured access rights schemes useless.
After searching, it seemed to me that the problem was in the jira-software-users group. I was advised to make a new group and in the Applications settings add access to Jira Software to it so that users can log in. Then I created a jira-developers group, gave it access to Jira-Software. As a result, this group began to have the same disadvantages as jira-software-users, that is, all its users see all projects and can change project roles in them.
So there are two problems:
1) users of the jira-software-users group see all projects (even if they are not assigned a role in this project);
2) any user in the project can change the role scheme (add new users and give them roles, change their roles, etc.).
It would also be nice to set it up so that a certain user group or role can see only the issues of the project, and not the entire project with its settings. Maybe I didn’t understand something and the problem is not in the jira-software-users group.
After I removed "Reporter" role, the permissions began to work as I wanted.
Welcome to community!
i've used roles in many permission schemes and this doesn't cause the issue, there seems to be something else at play unrelated to permissions here
In the permissions scheme verify the browse permission role isn't applied to that group would be the only permission based thing
Other than that you would need to look at the global permission and make sure they don't have admin access. You can also check the groups and verify admin isnt next to that groups name. If it is you need to remove admin from that group
Without seeing your instance though or having screenshots of all the places it's hard to diagnose. However, I can assure you the only way this is permissions related is that the Browse Project permission has a group on it or that group is in the project roles as some role for every project. Otherwise it's not related to permissions
Best,
Clark
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks for the answer!
I am attaching pictures of "Global permissions", "Users and roles", and "Permissions" of project.
As you can see this is a very simple configuration. But with these settings, any user in the "jira-software-users" group can open the "Project settings", enter the "Users and roles" and assign themselves the "Administrators" role.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I solved this problem, it was my mistake.
I didn't fully understand the meaning of the "Reporter" role. After I removed this role, the permissions began to work as I wanted.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.