Modify

Opened 9 years ago

Closed 9 years ago

#3642 closed defect (fixed)

[0.11][patch] Ticket update action require TICKET_MODIFY permission instead of TICKET_ADMIN

Reported by: anonymous Owned by: Odd Simon Simonsen
Priority: highest Component: XmlRpcPlugin
Severity: normal Keywords:
Cc: Trac Release: 0.11

Description

Currently resolve action require TICKET_ADMIN permission

Attachments (2)

tracrpc.svn.diff (882 bytes) - added by anonymous 9 years ago.
patch
clipboard.txt (2.2 KB) - added by Steffen Pingel 9 years ago.
Patch from http://trac-hacks.org/attachment/ticket/1075/ticket-validate.diff

Download all attachments as: .zip

Change History (9)

Changed 9 years ago by anonymous

Attachment: tracrpc.svn.diff added

patch

comment:1 Changed 9 years ago by Odd Simon Simonsen

#3835 closed as duplicate.

comment:2 Changed 9 years ago by Steffen Pingel

Priority: normalhighest
Summary: Ticket update action require TICKET_MODIFY permission insted of TICKET_ADMIN[0.11] Ticket update action require TICKET_MODIFY permission instead of TICKET_ADMIN
Trac Release: 0.100.11

comment:3 Changed 9 years ago by Steffen Pingel

Summary: [0.11] Ticket update action require TICKET_MODIFY permission instead of TICKET_ADMIN[0.11][patch] Ticket update action require TICKET_MODIFY permission instead of TICKET_ADMIN

comment:4 Changed 9 years ago by Odd Simon Simonsen

Owner: changed from Alec Thomas to Odd Simon Simonsen

With workflow, the actual answer is: It depends. With the latest workflow patch on #1075, I'm using the Trac ticket update infrastructure to validate ticket - including any permissions. If the user isn't allowed through web, he/she won't be allowed to make the update using xmlrpc anyway. I'll update the patch to set TICKET_VIEW as minimum needed permission.

comment:5 Changed 9 years ago by Steffen Pingel

Sounds good. We can probably mark this as duplicate then.

comment:6 Changed 9 years ago by Odd Simon Simonsen

Nah. Not really a duplicate - I'll close it together with other tickets as fixed after commit.

comment:7 Changed 9 years ago by Odd Simon Simonsen

Resolution: fixed
Status: newclosed

Fixed as part of [6045].

Modify Ticket

Change Properties
Set your email in Preferences
Action
as closed The owner will remain Odd Simon Simonsen.
The resolution will be deleted.

Add Comment


E-mail address and name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.