[rt-users] urgent: disable search for new watchers

Kevin Falcone falcone at bestpractical.com
Fri Jun 19 10:10:10 EDT 2009


On Jun 19, 2009, at 4:22 AM, Violetta J. Wawryk wrote:

> yes I have to make him priviledged because he is a kind of controll
> instance who has to see what orders (a ticket is a order) have been  
> made.
>
> Thanks to all who answered. I cannot believe that noone ever thought  
> of
> this as a security bug.
>
> @Kevin: no I did not grant ShowConfigTab to anyone, to be honest I
> didn't even know that this one existed.

I just installed RT 3.6.1 and made a privileged tester user
that has been globally granted
CreateTicket
ReplyToTicket
SeeQueue
ShowTicket

When logging in as this user, I don't see the Configuration tab.
How do I navigate to the User search page to test userid doesn't
contain xyz?

-kevin




More information about the rt-users mailing list