[rt-users] Watch right isn't neither set globally nor to any of my queues but unprivileged users can still change requestor or Cc (rt 4.0.1)

Kevin Falcone falcone at bestpractical.com
Wed Jul 6 09:57:42 EDT 2011


On Wed, Jul 06, 2011 at 03:23:10PM +0200, Fabian Unfried wrote:
>    another question, I didn't set the "Watch" right neither globally nor in any of my queues for
>    unprivileged user (also not for everyone, AdminCc, Cc, Owner or Requestor only for privileged
>    users), but when an unprivileged user creates a ticket he can see and change the requestors
>    and Cc field. Is this usual behavior? I don't want my user to be able to create tickets for
>    other users or that they can remove themselves as requestor, did I miss another right which I
>    have to revoke?

The To and CC lines in the SelfService interface ticket create form
are standard RT

-kevin
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 195 bytes
Desc: not available
URL: <http://lists.bestpractical.com/pipermail/rt-users/attachments/20110706/082ce65a/attachment.sig>


More information about the rt-users mailing list