Modify

Opened 9 years ago

Closed 8 years ago

#3642 closed defect (fixed)

[0.11][patch] Ticket update action require TICKET_MODIFY permission instead of TICKET_ADMIN

Reported by: anonymous Owned by: Odd Simon Simonsen
Priority: highest Component: XmlRpcPlugin
Severity: normal Keywords:
Cc: Trac Release: 0.11

Description

Currently resolve action require TICKET_ADMIN permission

Attachments (2)

tracrpc.svn.diff (882 bytes) - added by anonymous 9 years ago.
patch
clipboard.txt (2.2 KB) - added by Steffen Pingel 8 years ago.
Patch from http://trac-hacks.org/attachment/ticket/1075/ticket-validate.diff

Download all attachments as: .zip

Change History (9)

Changed 9 years ago by anonymous

Attachment: tracrpc.svn.diff added

patch

comment:1 Changed 8 years ago by Odd Simon Simonsen

#3835 closed as duplicate.

comment:2 Changed 8 years ago by Steffen Pingel

Priority: normalhighest
Summary: Ticket update action require TICKET_MODIFY permission insted of TICKET_ADMIN[0.11] Ticket update action require TICKET_MODIFY permission instead of TICKET_ADMIN
Trac Release: 0.100.11

comment:3 Changed 8 years ago by Steffen Pingel

Summary: [0.11] Ticket update action require TICKET_MODIFY permission instead of TICKET_ADMIN[0.11][patch] Ticket update action require TICKET_MODIFY permission instead of TICKET_ADMIN

comment:4 Changed 8 years ago by Odd Simon Simonsen

Owner: changed from Alec Thomas to Odd Simon Simonsen

With workflow, the actual answer is: It depends. With the latest workflow patch on #1075, I'm using the Trac ticket update infrastructure to validate ticket - including any permissions. If the user isn't allowed through web, he/she won't be allowed to make the update using xmlrpc anyway. I'll update the patch to set TICKET_VIEW as minimum needed permission.

comment:5 Changed 8 years ago by Steffen Pingel

Sounds good. We can probably mark this as duplicate then.

comment:6 Changed 8 years ago by Odd Simon Simonsen

Nah. Not really a duplicate - I'll close it together with other tickets as fixed after commit.

comment:7 Changed 8 years ago by Odd Simon Simonsen

Resolution: fixed
Status: newclosed

Fixed as part of [6045].

Modify Ticket

Change Properties
Set your email in Preferences
Action
as closed The owner will remain Odd Simon Simonsen.
The resolution will be deleted. Next status will be 'reopened'.

Add Comment


E-mail address and name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.