Help Desk Software & Beyond
May 17, 2012, 06:05:46 AM
Welcome,
Guest
. Please
login
or
register
.
To post messages
you need to register. We apologize for inconvenience, but this is to prevent spam.
Registration is instant (no email verification) and we do not ask for any personal information.
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
:
Welcome to Help Desk Software forum!
Home
Help
Search
Login
Register
Help Desk Software & Beyond
>
Forum
>
Trouble Ticket Express
>
Troubleshooting/Setup
(Moderator:
Sparky
) >
Operators Can see ANY Ticket
Pages: [
1
]
« previous
next »
Print
Author
Topic: Operators Can see ANY Ticket (Read 205 times)
Derwood
Newbie
Karma: 1
Posts: 19
Operators Can see ANY Ticket
«
on:
November 13, 2011, 07:56:42 AM »
G'day All,
I have had one of the operators of our setup of TTX demonstrate something to me that worries me a little. When logged in and by using the web address line in any browser they can look at any ticket they have access to. An example address is shown below;
http://(your web address)/ttx.cgi?cmd=ticket&sid=&key=16462&style=
by changing the TTX number, they can then view any ticket they like. Regardless of if they belong to that group and should have visibility or not.
I block groups from some of my operators for very good reasons and I am wondering if we can do something about this?
(Using TTX V3.0 and SQL, not 100% sure of the server details)
thanks
Darren
«
Last Edit: November 13, 2011, 07:58:19 AM by Derwood
»
Logged
Sparky
Moderator
Hero Member
Karma: 83
Posts: 2,228
stop pushing all those buttons
Re: Operators Can see ANY Ticket
«
Reply #1 on:
November 14, 2011, 11:11:27 AM »
This is how TTX has always worked.
Anybody
, not just operators, can view
any
ticket if they have the corresponding access key. However, somebody who is not logged in as an operator would need the full long version of the key.
Feel free to send a message to Alex at his helpdesk if you feel that your setup is not secure enough.
«
Last Edit: November 14, 2011, 11:17:25 AM by Sparky
»
Logged
Did you update the paths in ttxcfg.cgi after moving TTX to your new location?
To those seeking help.... please report back when you figure it out.
Alex
Administrator
Hero Member
Karma: 22
Posts: 605
Re: Operators Can see ANY Ticket
«
Reply #2 on:
November 14, 2011, 04:20:33 PM »
Thanks for heads up. The problem is fixed, updated files are available through SVN repositories:
version 3.01 (latest official release)
https://www.unitedwebcoders.com/fisheye/browse/TTX/release-3.01
or
https://www.unitedwebcoders.com/fisheye/browse/~raw,r=850/TTX/release-3.01/TTXTicket.pm
or
http://svn.unitedwebcoders.com:8082/svn/ttx/release-3.01/
latest development snapshot:
https://www.unitedwebcoders.com/fisheye/browse/TTX/trunk
or
http://svn.unitedwebcoders.com:8082/svn/ttx/trunk/
Logged
Follow me on:
LinkedIn
Pages: [
1
]
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Forum
-----------------------------
=> News, Announcements & Rules
=> Trouble Ticket Express
===> Troubleshooting/Setup
===> Modifications
=> HelpDesk Connect
Loading...