Permissions
Permissions should be evaluated from the authenticated identity and project membership.
On this page ▾
Typical hierarchy:
text
System
│
├── administrator
│
└── Project
│
├── owner/admin
├── maintainer
├── contributor
└── viewerExact roles are implementation-specific.
Security principle
Every API operation that reads or mutates project/issue data should enforce authorization server-side.
A user being able to see a project page is not sufficient evidence that the user is authorized to mutate every issue within that project.
Something wrong or missing on this page?Report a docs issue