[rt-users] RT: Essentials -- ToDo example

Ruslan Zakirov ruslan.zakirov at gmail.com
Wed Oct 26 00:05:32 EDT 2005


On 10/25/05, Roderick A. Anderson <raanders at acm.org> wrote:
> Before I post a bug report I wanted to find out if I misunderstood the
> example on pages 113-114 "Personal To-Do Lists".
>
> After a "miss-reading" I changed the ACL's to the correct setting but a
> ToDo Queue item I created is visible to other, normal-Privledged, users.
>
> Initially I set the ACLs so Everyone ( instead of Priviledged Users )
> could SeeQueue, CreateTicket, and OwnTicket.  But the Owner group was
> set correctly(?): CommentOnTicket, ShowTicket, ShowTicketComments,
> ReplyToTicket, and ModifyTicket.
>
> I accessed the Ticket ( as another user ) with the Everyone ACLs set
> then went back and corrected them but can still access the ticket as
> that and other users.
May be your users have 'ShowTicket' right for this queue. Didn't get
book yet, but I think it uses roles to delegate correct rights to
user. You have to revoke 'ShowTicket' right from all users and groups
on this queue and only grant it via Requestor and/or Owner role.

>
> Did I missunderstand the ACLs?  Can there be a Queue everyone can access
> but they can only see their tickets?
>
> Oh yeah!  RT 3.4.4
>
>
> Rod


--
Best regards, Ruslan.



More information about the rt-users mailing list