Search's ticket count includes tickets I don't have permission to view

Hi All;

We run multiple queues for a few self-contained IT groups. These groups do
not have permissions to one another’s queues.

One of these groups reported that ticket count (and pagination!) resulting
from a search occurs before the tickets are filtered on permission to view.

Here’s a nice first-person summary:

I just did a search for “mail”, it reported “Found 192 tickets” and only
displayed six items on the first page, one on the second, none on the
third page, and none on the fourth page. 7 != 192

We’re running 3.6.5 on Ubuntu. I’ve read through some of the changelogs on
the blog, but didn’t see anything about this issue.

Can someone tell me if this problem has already been addressed in 3.6.6-7 or
3.8? Alternatively, are you experiencing this same issue in one of these
versions?

Much Thanks,

Isaac Vetter
College of Science
Purdue University

smime.p7s (2.37 KB)

Hi All;

We run multiple queues for a few self-contained IT groups. These
groups do
not have permissions to one another’s queues.

One of these groups reported that ticket count (and pagination!)
resulting
from a search occurs before the tickets are filtered on permission
to view.

If you come up to 3.8, you can use the UseSQLForACLChecks config
option to fix this.

-kevin