[ZBX-12441] {USER.FULLNAME}, {ESC.HISTORY}, {EVENT.ACK.HISTORY} macros open the user full names without checking for access rights Created: 2017 Jul 30  Updated: 2024 Apr 10  Resolved: 2017 Oct 10

Status: Closed
Project: ZABBIX BUGS AND ISSUES
Component/s: Server (S)
Affects Version/s: 3.0.10, 3.2.7, 3.4.0alpha2
Fix Version/s: 3.0.12rc1, 3.2.9rc1, 3.4.3rc1, 4.0.0alpha1, 4.0 (plan)

Type: Problem report Priority: Minor
Reporter: Sergejs Paskevics Assignee: Viktors Tjarve
Resolution: Fixed Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Issue Links:
Sub-task
depends on ZBX-12655 Users from different groups has acces... Closed
depends on ZBX-12887 Zabbix user can see super administrat... Closed
Team: Team A
Sprint: Sprint 13, Sprint 14, Sprint 15, Sprint 16, Sprint 17, Sprint 18
Story Points: 4

 Description   

Reproduce the problem:
1. Add regular user to send message in acknowledgement configuration;
2. Login like Zabbix Administrator, select problem and click 'Bulk acknowledge' button;
3. Add some message and click 'Acknowledge'
4. Login like regular user and check Event details page
Result: Regular user in column 'User' see 'Inaccessible user' value, if it message was sent by Admin - OK
5. Open 'Action log' and check message to regular user

Result: Outgoing message contain text - Zabbix Administrator (Admin) acknowledged problem
Expected: Outgoing message contain text - Inaccessible user acknowledged problem



 Comments   
Comment by Viktors Tjarve [ 2017 Aug 31 ]

Fixed in development branch svn://svn.zabbix.com/branches/dev/ZBX-12441

Comment by Viktors Tjarve [ 2017 Sep 01 ]

In frontend message content of users from different groups still can be viewed. To fix that I opened a new ticket - ZBX-12655.

Comment by Vladislavs Sokurenko [ 2017 Sep 19 ]

Successfully tested

Comment by Viktors Tjarve [ 2017 Oct 05 ]

Released in:

  • 3.0.12rc1 r73194
  • 3.2.9rc1 r73196
  • 3.4.3rc1 r73198
  • 4.0.0alpha1 r73199
Generated at Thu Apr 25 19:07:52 EEST 2024 using Jira 9.12.4#9120004-sha1:625303b708afdb767e17cb2838290c41888e9ff0.