Users with ticket.agent can edit user details

Infos:

  • Used Zammad version: 6.4.1
  • Used Zammad installation type: (source, package, docker-compose, …) source
  • Operating system: Windows 11
  • Browser + version: Edge Stable

Expected behavior:

  • From users´s perspective who has ticket.agent permissions it should not be possible to select user → action → edit → and then edit user details and set status as active/inactive.

Actual behavior:

  • It is possible for user with ticket.agent permission to edit user’s details and deactivate account.

Steps to reproduce the behavior:

  • Select any ticket, select user who created the ticket, take “Action” from top right, select “Edit” and edit any details.

Hi! Am i configuring or doing something wrong? From my point of view it is unwanted option that any agent could change user´s details. Is there any way to mitigate this or is this intended behaviour?

Thank you
Taavi

Hi @mankipisness. Never heard of ticket.admin. What is this?

Hi!
Sorry, i meant ticket.agent and i now edited my post. Thanks for noticing!

No issue at all, it’s designed like this.

Got it, thanks for your input!

This topic was automatically closed 7 days after the last reply. New replies are no longer allowed.