[rt-users] Custom Fields and Rights Question / maybe a bug

Ruslan Zakirov ruz at bestpractical.com
Wed Aug 8 10:13:33 EDT 2007


On 8/8/07, Ham MI-ID, Torsten Brumm <torsten.brumm at kuehne-nagel.com> wrote:
> Hi RT Users, Developers,
>
> i'm not 100% sure if this is a bug or if i'm again too dumb...
>
> For a Custom Field, I can grant the following Group Rights:
>
> SeeCustomField
> ModifyCustomField
> AdminCustomField
>
> >From my point of understanding, SeeCustomFields allows a user to see the CF and it's content, but not to change it?
right

>
> ModifyCustomFields grant him the right to change the Content of the CF and AdminCF grants him the right to change this CF, is this correct so far?
AdminCF allow user to admin a CF, add new possible values, change type...
ModifyCF allow user to modify value(s) of a CF on tickets or objects
this particular CF applies to.

>
> If the point above is correct, then if a user that only have the rights SeeCustomField should only be able to see this field and content, but should not be able to change the content?
right.

>
> OK, now my problem and why I'm thinking that's a bug...
>
> If a user creates a ticket in a queue with a custom field assigned and he has only the right SeeCustomField at this CF, he should see the field but should not be able to enter something there?!? But he is...!...is this the correct way of handling the ACL or do I something wrong?
Yeah, there is a small bug on create. User see fields he can see even
if he can't modify them, but as far as I know user gets 'permission
denied' after creation for fields he can't modify.

In 3.7 development branch we don't show fields user can't modify on
the create ticket page anymore. I think we can backport that fix.

>
> Its under RT 3.6.4 and I have double checked the rights, the global rights, group rights and user rights...
>
> Any Ideas or hints or understand I the rights Setup for CF totally wrong???
> --
>  Thanks in advance
>  ....
>     : Torsten Brumm
>     :
>     : Kuehne + Nagel
>     : HAM - MI-ID
>     :
>     : Bauerbergweg 23-25
>     : 22111 Hamburg
>     :
>     : +49 (40) 30333 3199
>     : +49 (40) 30333 44 3199
>     :
>     : torsten.brumm at kuehne-nagel.com
>     : www.kn-portal.com
>     : icq: 78258840
>     ....
>
>
> Kühne + Nagel (AG & Co.) KG, Geschäftsleitung: Hans-Georg Brinkmann (Vors.), Uwe Bielang (Stellv.), Dr. Björn Johansson (Stellv.), Bruno Mang, Alfred Manke, Thorsten Meincke, Mark Reinhardt (Stellv.), Tim Scharwath, Jens Wollesen Sitz: Bremen, Registergericht: Bremen, HRA 21928, USt-IdNr.: DE 812773878, Persönlich haftende Gesellschaft: Kühne & Nagel A.G., Sitz: Contern/LuxemburgGeschäftsführender Verwaltungsrat: Klaus-Michael Kühne
> _______________________________________________
> http://lists.bestpractical.com/cgi-bin/mailman/listinfo/rt-users
>
> Community help: http://wiki.bestpractical.com
> Commercial support: sales at bestpractical.com
>
>
> Discover RT's hidden secrets with RT Essentials from O'Reilly Media.
> Buy a copy at http://rtbook.bestpractical.com
>


-- 
Best regards, Ruslan.


More information about the rt-users mailing list