[rt-users] Watch right isn't neither set globally nor to any of my queues but unprivileged users can still change requestor or Cc (rt 4.0.1)

Kevin Falcone falcone at bestpractical.com
Wed Jul 6 10:19:58 EDT 2011


On Wed, Jul 06, 2011 at 04:12:27PM +0200, Fabian Unfried wrote:
> Is there a way to get rid of them? As I said I don't want my user to be able to change the requestor to something else than themselves and at the moment I don't think I'll use the Cc feature in the ticket create form.

You'll need to make a local modification to either turn those into
hidden form elements or use CSS/JS to hide them from the user but
still allow the Requestor to submit.

-kevin


> Am 06.07.2011 um 15:57 schrieb Kevin Falcone:
> 
> On Wed, Jul 06, 2011 at 03:23:10PM +0200, Fabian Unfried wrote:
>   another question, I didn't set the "Watch" right neither globally nor in any of my queues for
>   unprivileged user (also not for everyone, AdminCc, Cc, Owner or Requestor only for privileged
>   users), but when an unprivileged user creates a ticket he can see and change the requestors
>   and Cc field. Is this usual behavior? I don't want my user to be able to create tickets for
>   other users or that they can remove themselves as requestor, did I miss another right which I
>   have to revoke?
> 
> The To and CC lines in the SelfService interface ticket create form
> are standard RT
> 
> -kevin
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 195 bytes
Desc: not available
URL: <http://lists.bestpractical.com/pipermail/rt-users/attachments/20110706/ebfb5a9d/attachment.sig>


More information about the rt-users mailing list