[rt-users] privs for self-service ticket submission?

Bob Goldstein bobg at uic.edu
Mon Jul 5 12:35:18 EDT 2004


RT 3.2.0, perl 5.8.3, fcgi, apache 1.3.29

As a non-priv user, I can log on and see the tickets
I've opened by email.

  1. The list of tickets has 3 columns: Subject, Status, Owner.
     But the owner never shows. Even when I examine the ticket
     details, I can't (as requestor, but un-priv user) see who
     the owner is, who changed the status, who stole or assigned
     the ticket, etc. Even who added an append. (BTW, if you
     "reply" to a "comment", the comment is included in the
     reply, which is now visible to the user! And, due to the way
     replies work, the userid of the original commenter is
     included in the text of the append. That's a very easy way
     for hidden comments to leak out, due to human error.)

     A. If RT is going to hide all this, at the very least
        it should be a bit more subtle.  Don't show the Owner
        column on the list of open tickets, if you aren't
        going to show any owners.

     B. What privs do I need to assign, so that users can
        see this info?  In my context, it's not useful to
	hide who did what.  

   2. Now, as non-priv user, I want to submit a new Ticket.
      Can't do it, because none of the queues are visible in
      the drop-down list.  Adding SeeQueue doesn't help,
      either global or per-queue.  What priv is needed?

         bobg



More information about the rt-users mailing list