[INFRA-204] Current workflow does not allow transitions from Open Created: 04/Jun/18  Updated: 05/Apr/19

Status: Open
Project: Software Development Infrastructure
Component/s: None
Affects Version/s: None
Fix Version/s: None

Type: Bug Priority: Major
Reporter: cloomis Assignee: yuki.moritani
Resolution: Unresolved Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Issue Links:
Duplicate
is duplicated by INFRA-200 cannot mark ticket as in review or done Won't Fix
Relates
relates to INFRA-200 cannot mark ticket as in review or done Won't Fix

 Description   

The Workflow button on Issue pages is now just an Open button, and not a pulldown. I think this is a Workflow issue and not a screen issue, since my personal Kanban does not allow me to move issues from Backlog to In Progress. The error is: We can't move this issue to In Progress. Check if your workflow allows this transition and if all transition conditions are met.



 Comments   
Comment by cloomis [ 04/Jun/18 ]

On the other had, the (single) Workflow has not been changed since 2016-07, and there are arcs from All to each of the states.

Comment by hassan [ 04/Jun/18 ]

Raised to blocker. This new behavior is affecting pretty much every open JIRA ticket across all projects as far as I can see.

Comment by shimono [ 04/Jun/18 ]

mark this as dup to INFRA-200.

Comment by hassan [ 04/Jun/18 ]

This is different. All options to change workflow are now gone. And this appears to have happened over this weekend. Only an 'open' button remains.

I will relate the two issues but I think there is no duplicate.

Comment by shimono [ 04/Jun/18 ]

hrm.. that seems the same as what I've reported at INFRA-200... > only 'open'
we had some change on group definition to switch entirely into LDAP recently, but not sure it relates or not.

Comment by hassan [ 04/Jun/18 ]

Ok, perhaps you are correct - it's strange that it is now happening across all projects though.

I just ran the integrity checker BTW and it shows no problems. So it could be a user privilege problem. Will try re-indexing first.

Comment by hassan [ 05/Jun/18 ]

Looking at the transitions under admin, only users in group jira-developers can execute this transition.

The only user in that group is pfs-jira-admin  jira@pfs.ipmu.jp . 

Adding myself explicitly to the jira-developers role seems to fix the problem, but for me alone. We need to find a general solution of restoring all PFS developers to this role.

As shimono mentions before, there has been some changes made recently to the jira-developers group with respect to LDAP. It does not make sense to me why the only user is jira@pfs.ipmu.jp . shimono: can you check that this is correct?

Comment by hassan [ 05/Jun/18 ]

As it is important for developers to make transitions, I will in the next few hours (if there are no objections) temporarily add the group jira-ldap-users to the jira-developers list.

This would mean that pretty much all users will have access to all transitions. But I believe we can trust people during this temporary period. And I believe any minor abuse is better than to lock transitions from developers.

Comment by shimono [ 05/Jun/18 ]

jira-(administrators|developers|users) are built in group wihtin JIRA application, jira-ldap-* are defined in LDAP for SSO. pfs-jira-admin is the sole admin account in the JIRA local dictionary created at the first installation but not from LDAP - so this account should be in all of built in groups (if no there is no control on issue happened).
to prevent misoperation, especially to perform messy additional configuration at external from LDAP, we set jira-ldap-* as default group(s) for accounts from LDAP.

Comment by hassan [ 05/Jun/18 ]

Having pfs-jira-admin in the jira-developers group is fine.
But it seems that non of the jira-ldap-* users are being propagated to the jira-developers group.
I can add them all explicitly, but there does seem to be an LDAP issue.

Comment by hassan [ 06/Jun/18 ]

Because it is not possible to have one JIRA group as a member of another, I have added, temporarily, all the individual members of the jira-ldap-users group to the jira-developers group.

This change should be reverted as soon as a long-term solution is understood and implemented.

Comment by hassan [ 06/Jun/18 ]

Priority dropped from blocker to major. I suggest that this issue remains open until the aforementioned long term solution is found,

Generated at Sat Feb 10 16:50:28 JST 2024 using Jira 8.3.4#803005-sha1:1f96e09b3c60279a408a2ae47be3c745f571388b.