Description
Goal
Extend public read-only projects with an opt-in issue-submission capability. This builds on TRACK-18 but remains disabled by default.
Acceptance criteria
- A public read-only project has a separate
Allow public issue creationsetting, disabled by default. - Only the project owner or an authorized administrator can change the setting.
- The option is configurable from the same project access/member-management area as public read-only access.
- The option is effective only while public read-only access is enabled.
- When enabled, an authenticated account without project membership can create an issue in the project.
- Anonymous visitors are prompted to sign in and cannot create issues.
- Public issue submitters can set only the fields explicitly exposed by the submission form and cannot edit the issue or perform other project mutations unless separately authorized.
- The created issue records the submitting account as reporter and follows normal project defaults.
- Server-side authorization enforces the setting for UI, API, and MCP paths; hiding the button is not the security boundary.
- Add tests for the default-disabled state, anonymous users, enabled authenticated submission, disabled public access, blocked users, and rejected follow-up mutations.
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.
Comments
0No comments.