Permissions and linking tickets

Moderator: crythias

Post Reply
Mothra
Znuny expert
Posts: 189
Joined: 26 Oct 2010, 15:04
Znuny Version: 3.2.11

Permissions and linking tickets

Post by Mothra »

Which group permission is concerned with the ability to link tickets? I have just created a user that only has "read-only" and "move-into" permission for a particular group/queue, yet this user can still find the ticket in a search and link it to any other ticket they have read access to.

I would like to prevent this if at all possible - is there an extra configuration setting that restricts the ability to link tickets?
OTRS 3.2.11 on Centos 6.4 with MySQL 5.0. Agents and internal customers authenticate via Active Directory.
crythias
Moderator
Posts: 10169
Joined: 04 May 2010, 18:38
Znuny Version: 5.0.x
Location: SouthWest Florida, USA
Contact:

Re: Permissions and linking tickets

Post by crythias »

Even if they can link to it, if they don't have permission for it for the queue the ticket is in, they shouldn't be able to see the ticket.

Edit: See the ticket: maybe, but zoom/see details? probably not. The search may show ticket numbers, titles, queues, owner, however.
OTRS 6.0.x (private/testing/public) on Linux with MySQL database.
Please edit your signature to include your OTRS version, Operating System, and database type.
Click Subscribe Topic below to get notifications. Consider amending your topic title to include [SOLVED] if it is so.
Need help? Before you ask
Mothra
Znuny expert
Posts: 189
Joined: 26 Oct 2010, 15:04
Znuny Version: 3.2.11

Re: Permissions and linking tickets

Post by Mothra »

crythias wrote:Even if they can link to it, if they don't have permission for it for the queue the ticket is in, they shouldn't be able to see the ticket.

Edit: See the ticket: maybe, but zoom/see details? probably not. The search may show ticket numbers, titles, queues, owner, however.
The read-only access allows them to zoom in on a ticket and gives them the following actions: "Back - History - Print - Link". It's that last one that surprised me - surely linking a ticket to another ticket constitutes a change, and goes beyond "read-only" access?
OTRS 3.2.11 on Centos 6.4 with MySQL 5.0. Agents and internal customers authenticate via Active Directory.
crythias
Moderator
Posts: 10169
Joined: 04 May 2010, 18:38
Znuny Version: 5.0.x
Location: SouthWest Florida, USA
Contact:

Re: Permissions and linking tickets

Post by crythias »

Mothra wrote:
crythias wrote:Even if they can link to it, if they don't have permission for it for the queue the ticket is in, they shouldn't be able to see the ticket.

Edit: See the ticket: maybe, but zoom/see details? probably not. The search may show ticket numbers, titles, queues, owner, however.
The read-only access allows them to zoom in on a ticket and gives them the following actions: "Back - History - Print - Link". It's that last one that surprised me - surely linking a ticket to another ticket constitutes a change, and goes beyond "read-only" access?
Links are bi-directional, so technically it's a change, on the other hand hyperlinking to the ticket is a feasible accomplishment as well, and does not involve changing the linked-to ticket at all.
OTRS 6.0.x (private/testing/public) on Linux with MySQL database.
Please edit your signature to include your OTRS version, Operating System, and database type.
Click Subscribe Topic below to get notifications. Consider amending your topic title to include [SOLVED] if it is so.
Need help? Before you ask
Post Reply