[rt-users] goto ticket error (security problem)

Michael Shanks mike at tekniq.org
Sat Mar 18 03:35:11 EST 2006


Hello

If I remove this right it corrects the problem, however my user now cannot
see his open or closed tickets also

-----Original Message-----
From: Jesse Vincent [mailto:jesse at bestpractical.com] 
Sent: 18 March 2006 03:23
To: Michael Shanks
Cc: rt-users at lists.bestpractical.com
Subject: Re: [rt-users] goto ticket error (security problem)




On Sat, Mar 18, 2006 at 02:00:26AM -0000, Michael Shanks wrote:
> Hello I am configuring a new helpdesk using request tracker, I notice one
> problem and I am wondering if you can help me with my configuration, 
>  
> When a user logs into the self service page they are presented with their
> open tickets, top right is also the goto ticket option, when the user
types
> in any ticket ID the ticket is shown to them even if they are not the
> original submitter, 
>  

You've granted "Everyone" the right to "ShowTicket"


-- 
No virus found in this incoming message.
Checked by AVG Free Edition.
Version: 7.1.385 / Virus Database: 268.2.4/283 - Release Date: 16/03/2006
 

-- 
No virus found in this outgoing message.
Checked by AVG Free Edition.
Version: 7.1.385 / Virus Database: 268.2.4/283 - Release Date: 16/03/2006
 




More information about the rt-users mailing list