Ticket #7608 (new defect)
Private ticket permission users can get ticket counts that include tickets they're not allowed to view
| Reported by: | jevans | Owned by: | |
|---|---|---|---|
| Priority: | normal | Milestone: | 0.12 |
| Component: | report system | Version: | 0.11.1 |
| Severity: | normal | Keywords: | query |
| Cc: | osimons |
Description
A user with private tickets permissions can still query how many tickets meet criteria even if they can't see the tickets listed or view them.
For instance they can type in query?status=!closed&priority=critical to get a count of how many critical defects are open.
I originally wrote this ticket on the PrivateTicketsPlugin (#3674) but heard that it's a problem in Trac core.
Attachments
Change History
Note: See
TracTickets for help on using
tickets.


