44 views

Description

A non-ITIL user (a user with no roles) can create Task-Outages via incidents or problems when the Task-Outage plugin is installed, regardless of the permissions that are set on the Outages table.

Steps to Reproduce

  1. Install the Task-Outage plugin (on the Fuji or Geneva platform).

  2. Impersonate a requester (no-roles) user.

  3. Create an Incident ticket and view that ticket through the ITIL interface.

  4. Under the form actions menu, create a Task-Outage.

  5. Scroll down to the bottom of the Incident form.

    Note that you do not see any Outages listed.

  6. Impersonate an ITIL user and go to the same Incident form.

    Note that the Outages were created by the non-ITIL user with default values.

Workaround

Create ACLs on the Task-Outage table that restrict users other than the itil role from creating records.

If you are able to upgrade, review the Fixed In or Intended Fix Version fields to determine whether any versions have a planned or permanent fix.


Related Problem: PRB671214

Seen In

Fuji Patch 11
Geneva Patch 6

Fixed In

Istanbul

Associated Community Threads

There is no data to report.

Article Information

Last Updated:2018-07-01 04:12:31
Published:2018-07-01