It looks like a bug to me. The only way I've been able to allow an unprivileged requestor to view outgoing e-mail is to turn him into a privileged user. Privileged users get a different Display.html than unprivileged users, and I think that's the difference.

I'm probably over-simplifying the program, but I grepped the source tree looking for 'ShowOutgoingEmail' and it only showed up in Ticket/Update.html. I would have expected to see it in a display-related file like Display.html or ShowEmailRecord.html.

Unfortunately I'm not a perl guru and can't completely grok the difference between SelfService/Display.html and Ticket/Display.html. Or it might be something in ShowEmailRecord.html, but I'm not seeing the "Abort" message anywhere and don't know whether the Abort function would cause the new window to open to the SelfService page instead of displaying the requested e-mail.

At 09:03 AM 3/2/2007, Joe Casadonte wrote:
On 3/1/2007 3:16 PM, Gene LeDuc wrote:

Is this a bug or expected behavior? Have I given the Requestor role the appropriate rights?

Just eyeballing it, it looks OK. Have you tried turning on debugging and looking in the log?


--
Gene LeDuc, GSEC
Security Analyst
San Diego State University
_______________________________________________
http://lists.bestpractical.com/cgi-bin/mailman/listinfo/rt-users

Community help: http://wiki.bestpractical.com
Commercial support: [EMAIL PROTECTED]


Discover RT's hidden secrets with RT Essentials from O'Reilly Media. Buy a copy at http://rtbook.bestpractical.com

Reply via email to