# \[SOLVED\] How to setup users with only access to issues

**URL:** <https://forum.gitea.com/t/solved-how-to-setup-users-with-only-access-to-issues/1011>\
**Category:** Install/Maintain/Configure\
**Created:** [March 17, 2019, 6:13pm UTC](https://forum.gitea.com/t/solved-how-to-setup-users-with-only-access-to-issues/1011 "2019-03-17T18:13:16Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![nodiscc](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/nodiscc/32/4811_2.png) [@nodiscc](https://forum.gitea.com/u/nodiscc)\
**Post date:** [March 17, 2019, 6:13pm UTC](https://forum.gitea.com/t/solved-how-to-setup-users-with-only-access-to-issues/1011/1 "2019-03-17T18:13:16Z")

</div>

Hi, I am trying to setup a Gitea instance with the following user account/organization/repository/team permissions:

**Organizations:**

- `mycorp`
- `anothercorp`

**Users:**

- User0 (admin)
- Bob
- Alice
- Eve

**Repositories:**

- `mycorp/projecta`
- `anothercorp/projectb`
- `anothercorp/projectc`

**Permissions:**

- Bob: can read/write everything on mycorp/projecta, but cannot access/view anothercorp’s repositories
- Alice: can read/write everything on anothercorp/projectb, cannot view mycorp’s repositories
- Eve: can only access antohercorp/projectc **issues** , cannot see the code/pulls, cannot list or access anything else.

I’m a bit lost regarding granular permissions, I only found how to add a user as _Collaborator_ on a project (in which case global access is either read/write/admin on _every feature_ in a repository), or how to add a _Reporter_ team in anothercorp with limited access to issues, and add that user to it, but this user still has to be added to _Collaborators_ on the repository else they can’t access it at all (then back to problem 1, has read/write access on the whole repo).

Can someone explain me how I should proceed to create users with these permission levels?

---

<div class="post-metadata">

**Author:** ![lunny](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/lunny/32/4701_2.png) [@lunny](https://forum.gitea.com/u/lunny)\
**Post date:** [March 18, 2019, 2:28am UTC](https://forum.gitea.com/t/solved-how-to-setup-users-with-only-access-to-issues/1011/2 "2019-03-18T02:28:17Z")

</div>

1. add Bob on mycorp’s owner team
2. add Alice on anothercorp’s owner team
3. create a new team on antohercorp which with read permission and only issues unit. The team only could access projectc and add Eve to this team.  
No Collaborator config.

---

<div class="post-metadata">

**Author:** ![gstg](https://avatars.discourse-cdn.com/v4/letter/g/7feea3/32.png) [@gstg](https://forum.gitea.com/u/gstg)\
**Post date:** [March 21, 2019, 2:13pm UTC](https://forum.gitea.com/t/solved-how-to-setup-users-with-only-access-to-issues/1011/3 "2019-03-21T14:13:56Z")

</div>

> [@nodiscc](#):
>
> Eve: can only access antohercorp/projectc **issues** , cannot see the code

create a new team on antohercorp which with read permission and only issues unit. The team only could access projectc and add Eve to this team.  
With this scenario, Eve CAN see repo code

---

<div class="post-metadata">

**Author:** ![nodiscc](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/nodiscc/32/4811_2.png) [@nodiscc](https://forum.gitea.com/u/nodiscc)\
**Post date:** [March 23, 2019, 1:04pm UTC](https://forum.gitea.com/t/solved-how-to-setup-users-with-only-access-to-issues/1011/4 "2019-03-23T13:04:13Z")

</div>

@lunny I can confirm what @gstg said: with this configuration, Eve can see the code, pull requests, along with everything else in projectc.

Is there a way to give a user _only_ issues access on a repository?

---

<div class="post-metadata">

**Author:** ![lunny](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/lunny/32/4701_2.png) [@lunny](https://forum.gitea.com/u/lunny)\
**Post date:** [March 24, 2019, 5:51am UTC](https://forum.gitea.com/t/solved-how-to-setup-users-with-only-access-to-issues/1011/5 "2019-03-24T05:51:22Z")

</div>

Which version did you use? Could you reproduce that on [https://try.gitea.io](https://try.gitea.io) ?

---

<div class="post-metadata">

**Author:** ![gstg](https://avatars.discourse-cdn.com/v4/letter/g/7feea3/32.png) [@gstg](https://forum.gitea.com/u/gstg)\
**Post date:** [March 24, 2019, 7:57pm UTC](https://forum.gitea.com/t/solved-how-to-setup-users-with-only-access-to-issues/1011/6 "2019-03-24T19:57:42Z")

</div>

1.7.4, latest (Version: d7542bf )  
In which version your scenario work?

I think is not need trying on [https://try.gitea.io](https://try.gitea.io) ( probably latest version, so same 1.7.4)

maybe just a notice:  
we have only read access permission, nowhere is NO read access for code, so i think that scenario is not possible

---

<div class="post-metadata">

**Author:** ![nodiscc](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/nodiscc/32/4811_2.png) [@nodiscc](https://forum.gitea.com/u/nodiscc)\
**Post date:** [March 24, 2019, 9:54pm UTC](https://forum.gitea.com/t/solved-how-to-setup-users-with-only-access-to-issues/1011/7 "2019-03-24T21:54:20Z")

</div>

Thanks, I found the answer to my question. Here is a similar setup, and it works:

**Create 3 users:**

- bob
- alice
- eve

**Create 2 organizations** (only 1 will be used in this example):

- mycorp
- anothercorp

**Create 3 private repositories for the organization** `anothercorp`:

- anothercorp-x
- anothercorp-y
- anothercorp-z

In anothercorp, **create 3 teams** :

- `developers_all_projects`:
  - Description: Developers for all anothercorp projects
  - Permissions: Write access to everything

- `developers_projectx`:
  - Description: Developers for anothercorp-x
  - Permissions: Write access to everything

- `reporters_projectx`:
  - Description: Bug reporters for anothercorp-x
  - Permissions: Write access to issues only

Add users to each team:

- `developers_all_projects`: bob
- `developers_projectx`: alice
- `reporters_projectx`: eve

**Add repositories to each team!** This is what I was missing. Eve was able to read everything on a project because it was a _public_ project (my mistake).

- `developers_all_projects`: anothercorp-x, y and z
- `developers_projectx`: anothercorp-x
- `reporters_projectx`: anothercorp-x

It works! Each user can only see/list repositories assigned to their team, with the permissions from their team. Only organization owners can list everything.

 ![gitea-5-anothercorp-repos-overview](https://us1.discourse-cdn.com/flex020/uploads/gitea/original/1X/2aced0abaeef74c8bcff0bf98f7abfbd540939a4.png)

**Teams are defined at organization level, but their permission levels only apply to repositories they’ve been given access to.** All areas of a public repository are always readable by everyone (even outside the org?).

Tested on Gitea 1.7.3 and 1.7.4

---

<div class="post-metadata">

**Author:** ![lunny](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/lunny/32/4701_2.png) [@lunny](https://forum.gitea.com/u/lunny)\
**Post date:** [May 11, 2026, 6:03pm UTC](https://forum.gitea.com/t/solved-how-to-setup-users-with-only-access-to-issues/1011/8 "2026-05-11T18:03:46Z")

</div>


