ChiliProject is not maintained anymore. Please be advised that there will be no more updates.
We do not recommend that you setup new ChiliProject instances and we urge all existing users to migrate their data to a maintained system, e.g. Redmine. We will provide a migration script later. In the meantime, you can use the instructions by Christian Daehn.
Permissions are only checked for top level menu entries (Bug #758)
When rendering menu items only the items with actions that the user is allowed to access should be rendered. Due to a bug in the MenuHelper the permission check is only done for top level menu items. Second level menu items, like e.g. the "New issue" item in the project menu are rendered without a permission check.
I have a fix for this bug on github: