ACL not removed?

Hello,

I’ve upgraded from 4.0 to 4.2.6 last week (but i don’t know if that
matter…).

I’ve discovered today that some access right are very strange.

The facts :
-> access right are ONLY on groups (never on users),
-> 2 users are member of the same groups : GroupId 1663 and 4777
-> user1 is older than user2.
-> the 2 users are privilegied, but Not admin,
-> user1 have restricted access to some queues (Ok)
-> user2 have full acces to ALL queues (Not Ok !!!)

So i’ve tried to disabled groups : the problem occur on groupId 4777 : when
it is disabled, all access are ok, and resctrict access working.

So i’ve removed ALL right to this group : that’s make no changes : when the
group is un-disabled, user1 has his normal and restricted access, but user2
have full access to all queues.
One more time, when i disable the groupId 4777 , all goes right.

So … i’m a bit lost …
Have you any idea ?

Thanks in advance.
Eric

So i’ve tried to disabled groups : the problem occur on groupId 4777 : when it
is disabled, all access are ok, and resctrict access working.

So i’ve removed ALL right to this group : that’s make no changes : when the

I have no idea what “removed ALL right to this group” means.

group is un-disabled, user1 has his normal and restricted access, but user2
have full access to all queues.
One more time, when i disable the groupId 4777 , all goes right.

So … i’m a bit lost …
Have you any idea ?

This implies there are other rights you don’t know about.
You can look in the ACL table for that rogue group.
You can also try the script from the RT-Extension-Utils package,
although I have no idea if it works on 4.2

-kevin