Uploaded image for project: 'ZABBIX BUGS AND ISSUES'
  1. ZABBIX BUGS AND ISSUES
  2. ZBX-3561

Read-only users can acknowledge triggers (doesn't properly check for write permission)

XMLWordPrintable

    • Icon: Patch request Patch request
    • Resolution: Won't fix
    • Icon: Major Major
    • None
    • 1.8.4
    • Frontend (F)
    • Linux, Apache, Php 5.3
    • Team C
    • Sprint 18

      In 1.8.4 (and earlier versions), guests (or other users with read only permissions) can acknowledge triggers that they can see, even without read/write permissions for the host. It's possible that this was by design, but that defies the Law of Least Astonishment, since giving someone read-only permissions shouldn't let them make any updates/changes.

      I have a patch (attached) that checks for read/write permissions for acknowledging triggers (on tr_status.php and acknow.php).

            Unassigned Unassigned
            laughingjudge Isaac Richter
            Team C
            Votes:
            5 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated:
              Resolved: