[rt-users] How can I prevent users from reading other queue's tickets?

Gilmar Santos Jr gilmarsantosjr at safernet.org.br
Tue Jul 4 11:11:02 EDT 2006


Hi Tim,

1. There is more than one permission involved. The "SeeQueue" and the
many "ShowTicket*". When someone doesn't have the "SeeQueue" permission 
it's still possible to see ticket, exactly as you described.
Remove the ShowTicket and related from those users that don't have the
SeeQueue.

2. If all users can see all queues that's true. Tickets in a queue you
can't see are not shown in your main page...

--
Gilmar Santos Jr

Tim Pritlove escreveu:
> Hi,
>
> I am using RT 3.2 and just found out two annoying things
>
> 1. people who have NO permissions for a queue can still read the
> ticket when they get the URL
> 2. tickets that do not have an owner get listed for every user of the
> system on the main page
>
> What can I do to prevent both things?
>
> Greetings
> Tim
> --Tim Pritlove, Discordian Evangelist, Chaos Computer Club
> <mailto:tim at ccc.de> <http://tim.geekheim.de/>
> <http://www.blinkenlights.de/>
> <jabber:tim at jabber.ccc.de> <gizmo://timpritlove> <skype://timpritlove>
> ------
> Ein Lebenskünstler gedeiht am besten im Spannungsfeld zwischen Bohème
> und Askese und ist als gelebtes Gesamtkunstwerk sinnstiftend für sich
> selbst. -- Wikipedia
>
>
> ------------------------------------------------------------------------
>
> _______________________________________________
> http://lists.bestpractical.com/cgi-bin/mailman/listinfo/rt-users
>
> Community help: http://wiki.bestpractical.com
> Commercial support: sales at bestpractical.com
>
>
> Discover RT's hidden secrets with RT Essentials from O'Reilly Media. 
> Buy a copy at http://rtbook.bestpractical.com
>
>
> We're hiring! Come hack Perl for Best Practical: http://bestpractical.com/about/jobs.html




More information about the rt-users mailing list