trackslash
TRACK-26 P2

Optionally allow authenticated public users to create project issues

0
All issues

Description

Goal

Extend public read-only projects with an opt-in issue-submission capability. This builds on TRACK-18 but remains disabled by default.

Acceptance criteria

  • A public read-only project has a separate Allow public issue creation setting, disabled by default.
  • Only the project owner or an authorized administrator can change the setting.
  • The option is configurable from the same project access/member-management area as public read-only access.
  • The option is effective only while public read-only access is enabled.
  • When enabled, an authenticated account without project membership can create an issue in the project.
  • Anonymous visitors are prompted to sign in and cannot create issues.
  • Public issue submitters can set only the fields explicitly exposed by the submission form and cannot edit the issue or perform other project mutations unless separately authorized.
  • The created issue records the submitting account as reporter and follows normal project defaults.
  • Server-side authorization enforces the setting for UI, API, and MCP paths; hiding the button is not the security boundary.
  • Add tests for the default-disabled state, anonymous users, enabled authenticated submission, disabled public access, blocked users, and rejected follow-up mutations.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

0
No comments.