You should grant ShowTicket via Requestor role for your customers rather than via direct granting to a group.
Use http://search.cpan.org/~ruz/RT-Extension-Utils-0.06/sbin/rt-check-user-right-on-ticketto check how particular user gets a right to a ticket. On Thu, Sep 19, 2013 at 3:08 PM, Aurelien Lafranchise < [email protected]> wrote: > Hello all, > > I am facing a confidentiality problem on my RT instance. > > My customers have access to RT to create ticket. In the interface they > have a search field they can use to go to a ticket number. The problem is > that they can put a ticket number and see the ticket even if it not one of > their tickets. > > I cannot find anywhere in the documentation or google any start of > explanation on that. > > Also all my customers are under the same group. > > Thanks for your help > Regards. > > AL > > -- > RT Training in New York, October 8th and 9th: > http://bestpractical.com/training > -- Best regards, Ruslan.
-- RT Training in New York, October 8th and 9th: http://bestpractical.com/training
