Private tickets still viewable via "Download in other formats"
|Reported by:||Owned by:||Noah Kantrowitz|
First of all, compliments for this plugin. It's actually something I've been searching for quite some time now, because our company would like to set up a test-installation of Trac as a bug/support platform for our customers. Obviously, we wouldn't want customer X looking into the tickets of customer Y.
Anyway, I was testing it a bit, and while watching a list of my own tickets (viewing the "All Active Tickets" report), I tried clicking the "Tab-delimited Text" link on the bottom of the page, to see what would happen. Unfortunately, in that file I just get a list of all available tickets, including all tickets reported by other users.
Can you fix this, so that the "Other format"-links take your TICKET_VIEW_* permissions into account? That way, the Comma- and Tab-delimited files would only display the tickets a user is permitted to see. If that's a no-go, can I somehow disable those links, or disable the feature in Trac?
Thanks in advance for your efforts!