[0.11][patch] Ticket update action require TICKET_MODIFY permission instead of TICKET_ADMIN

Reported by: anonymous Owned by: osimons
Priority: highest Component: XmlRpcPlugin
Severity: normal Keywords:
Cc: Trac Release: 0.11


Currently resolve action require TICKET_ADMIN permission

tracrpc.svn.diff (882 bytes) - added by anonymous 17 years ago.
clipboard.txt (2.2 KB) - added by Steffen Pingel 16 years ago.
Patch from

Changed 17 years ago by anonymous

Attachment: tracrpc.svn.diff added


comment:1 Changed 16 years ago by osimons

#3835 closed as duplicate.

comment:2 Changed 16 years ago by Steffen Pingel

Priority: normalhighest
Summary: Ticket update action require TICKET_MODIFY permission insted of TICKET_ADMIN[0.11] Ticket update action require TICKET_MODIFY permission instead of TICKET_ADMIN
Trac Release: 0.100.11

comment:3 Changed 16 years ago by Steffen Pingel

Summary: [0.11] Ticket update action require TICKET_MODIFY permission instead of TICKET_ADMIN[0.11][patch] Ticket update action require TICKET_MODIFY permission instead of TICKET_ADMIN

comment:4 Changed 16 years ago by osimons

Owner: changed from Alec Thomas to osimons

With workflow, the actual answer is: It depends. With the latest workflow patch on #1075, I'm using the Trac ticket update infrastructure to validate ticket - including any permissions. If the user isn't allowed through web, he/she won't be allowed to make the update using xmlrpc anyway. I'll update the patch to set TICKET_VIEW as minimum needed permission.

comment:5 Changed 16 years ago by Steffen Pingel

Sounds good. We can probably mark this as duplicate then.

comment:6 Changed 16 years ago by osimons

Nah. Not really a duplicate - I'll close it together with other tickets as fixed after commit.

comment:7 Changed 16 years ago by osimons

Resolution: fixed
Status: newclosed

Fixed as part of [6045].

