Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-34493

Delivery pipeline view shows even when the user doesn't have permissions on underlying projects

XMLWordPrintable

      When a restricted user is configured to only have permissions on a select number of projects he can still see delivery pipeline views (although empty) for other projects.

      Broken in Jenkins 1.656, delivery-pipeline-plugin 0.9.9
      This behavior broke somewhere after 0.9.5 of the delivery-pipeline-plugin.

      To reproduce:

      1. In global security configure project-based matrix authorization
        • Remove all permissions on the anonymous role
        • Add a test user and give him overall -> read permission and no other permissions
      2. Configure a delivery pipeline with one or two projects under it
      3. Note that the test user cannot see these projects
      4. Note that the test user can see the delivery pipeline view while he should not

            patbos Patrik Boström
            elindoorn Ernst Lindoorn
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: