Code of Conduct
Disable plugins
Is there an existing issue for this?
Version
11.0.7
Bug description
When a technician creates an approval request for a ticket and includes a comment/instruction for the approver, the assigned user (with a Self-Service profile) is able to edit or modify the technician's original text within that validation request. An approver should only be able to approve, reject, or add their own feedback, but never alter the description or comments written by the technician who initiated the request.
Relevant log output
Page URL
No response
Steps To reproduce
- Log in as a Technician or Admin
- Create a new approval request assigned to a standard Self-Service user, and add a text in the comment/description field
- Log in as the assigned Self-Service user
- Open the ticket
- Notice that the text field containing the technician's original comment is editable, allowing the user to change the context of what they are actually approving.
Your GLPI setup information
No response
Anything else?
No response
Code of Conduct
Disable plugins
Is there an existing issue for this?
Version
11.0.7
Bug description
When a technician creates an approval request for a ticket and includes a comment/instruction for the approver, the assigned user (with a Self-Service profile) is able to edit or modify the technician's original text within that validation request. An approver should only be able to approve, reject, or add their own feedback, but never alter the description or comments written by the technician who initiated the request.
Relevant log output
Page URL
No response
Steps To reproduce
Your GLPI setup information
No response
Anything else?
No response