Users with minimal rights now have full rights - why?

Hi,

I have a number of users set up with minimal rights (In Global user rights,
they only have comment and creat on ticlet set up).

Yet for some reason, when they log in, they have full rights (can even mess
with my root account). If I remve privlages, they still have the ability to
create tickets and put them in what ever queue they want.

I have even tried setting up some new restricted accounts, yet they also
have full admin when they log on.

I am not sure what has happened. Anyone got any ideas?
View this message in context: http://old.nabble.com/Users-with-minimal-rights-now-have-full-rights---why--tp26567308p26567308.html

Hi,

I have a number of users set up with minimal rights (In Global user rights,
they only have comment and creat on ticlet set up).

Yet for some reason, when they log in, they have full rights (can even mess
with my root account). If I remve privlages, they still have the ability to
create tickets and put them in what ever queue they want.

I have even tried setting up some new restricted accounts, yet they also
have full admin when they log on.

I am not sure what has happened. Anyone got any ideas?

Perhaps you granted some rights to ‘privileged’ or to ‘everybody’?

OK, Lets take this step by step.

I’m John Chapman, and my Customer is Joe Bloggs.

So….

I log in using my superuser account “John Chapman”.

I goto Configuration>Global>User Rights, and see that “Joe Bloggs” rights
are only set to “create ticket” and “commentonticket”. Good. That’s what I
want.

BUT when I log into Joe Bloggs account he can do everything just like he is
a superuser. I don’t want Joe Bloggs to be able to do that :frowning:

View this message in context: http://old.nabble.com/Users-with-minimal-rights-now-have-full-rights---why--tp26567308p26567488.html

Its ok I got it sorted.

Configuration>Global>Global Rights …under “everyone”, everthing
was active!

View this message in context: http://old.nabble.com/Users-with-minimal-rights-now-have-full-rights---why--tp26567308p26567612.html

John,

Unless you only have a few users, I /strongly/ recommend granting
privileges to groups, not to individual users. This will make rights
maintenance much easier in the future. When a new person needs the same
rights as others in a group, you merely add them to that group instead
of adding each right time after time after time.

Kenn
LBNLOn 11/29/2009 3:20 PM, John David Chapman wrote:

OK, Lets take this step by step.

I’m John Chapman, and my Customer is Joe Bloggs.

So….

I log in using my superuser account “John Chapman”.

I goto Configuration>Global>User Rights, and see that “Joe Bloggs” rights
are only set to “create ticket” and “commentonticket”. Good. That’s what I
want.

BUT when I log into Joe Bloggs account he can do everything just like he is
a superuser. I don’t want Joe Bloggs to be able to do that :frowning:

OK, Lets take this step by step.
I?m John Chapman, and my Customer is Joe Bloggs.
So?.
I log in using my superuser account ?John Chapman?.

I goto Configuration>Global>User Rights, and see that ?Joe Bloggs? rights
are only set to ?create ticket? and ?commentonticket?. Good. That?s what I
want.

BUT when I log into Joe Bloggs account he can do everything just like he is
a superuser. I don?t want Joe Bloggs to be able to do that :frowning:

Now go to Configuration>Global>Group Rights and inspect the rights
granted to Everyone and to Privileged.

Eleanor J. (Piglet) Evans, eje@panix.com
Customer Support, (212) 741-4400

Thanks Elenor and Kenn, good stuff. All working nicely; I’ll keep the access
rights down to users, as I’m using a minimal amount of users. Thanks!

John David Chapman wrote:

Hi,

I have a number of users set up with minimal rights (In Global user
rights, they only have comment and create on ticket set up).

Yet for some reason, when they log in, they have full rights (can even
mess with my root account). If I remove privileges, they still have the
ability to create tickets and put them in what ever queue they want.

I have even tried setting up some new restricted accounts, yet they also
have full admin when they log on.

I am not sure what has happened. Anyone got any ideas?

View this message in context: http://old.nabble.com/Users-with-minimal-rights-now-have-full-rights---why--tp26567308p26656224.html