Code of Conduct
Disable plugins
Is there an existing issue for this?
Version
10.0.27
Bug description
Since upgrading to GLPI 10.0.27, I have an issue when using the REST API to add an external requester to a ticket.
My use case is to assign an external requester to a ticket using an email address that is not necessarily associated with a GLPI user.
Before upgrading to GLPI 10.0.27, the following API request worked correctly:
{
"input": {
"tickets_id": 12345,
"users_id": 0,
"type": 1,
"use_notification": 1,
"alternative_email": "external.user@example.com"
}
}
The API endpoint is:
POST /apirest.php/Ticket_User
Since upgrading to 10.0.27, the exact same request returns:
HTTP CODE: 400
["ERROR_GLPI_ADD","You don't have permission to perform this action."]
Important details
The email address is correctly retrieved by my application.
The Session-Token and App-Token are valid.
The API user has the required rights on tickets.
I also tested the operation directly through the GLPI web interface while logged in as the same API user, and the operation works correctly.
I also tested with an Administrator profile, with the same result through the API.
Therefore, this does not appear to be a simple missing permission in the user's profile.
External requester
The requester is intentionally an external person and does not necessarily exist as a GLPI user.
Therefore:
is intentional, while:
"alternative_email": "external.user@example.com"
contains the actual requester email address.
This workflow was working correctly before upgrading to 10.0.27.
Possible regression
I noticed PR #22428:
#22428
which changes the API rights validation and mentions cases where the API can return:
ERROR_GLPI_ADD - You don't have permission to perform this action
while the corresponding operation works through the web interface.
My issue appears to be very similar, but with Ticket_User / ticket requester management rather than Item_SoftwareVersion.
Could the rights validation introduced/changed in this area also affect the creation of a Ticket_User with:
"users_id": 0,
"type": 1,
"alternative_email": "..."
?
Expected behavior
The API should allow an authorized user to add an external requester to a ticket using alternative_email, as it did before GLPI 10.0.27.
Actual behavior
The API returns:
ERROR_GLPI_ADD
You don't have permission to perform this action.
even though:
- the API user has the required ticket permissions;
- the same user can perform the operation through the web interface;
- an Administrator profile produces the same result;
- the email address is valid;
- the Session-Token and App-Token are valid.
Version
- GLPI: 10.0.27
- API: REST API
- Endpoint:
POST /Ticket_User
- Requester: external user (
users_id = 0)
- Authentication: Session-Token + App-Token
Could you please confirm whether this is an intentional change in the rights validation for Ticket_User, or a regression in 10.0.27?
Relevant log output
Page URL
No response
Steps To reproduce
No response
Your GLPI setup information
No response
Anything else?
No response
Code of Conduct
Disable plugins
Is there an existing issue for this?
Version
10.0.27
Bug description
Since upgrading to GLPI 10.0.27, I have an issue when using the REST API to add an external requester to a ticket.
My use case is to assign an external requester to a ticket using an email address that is not necessarily associated with a GLPI user.
Before upgrading to GLPI 10.0.27, the following API request worked correctly:
{ "input": { "tickets_id": 12345, "users_id": 0, "type": 1, "use_notification": 1, "alternative_email": "external.user@example.com" } }The API endpoint is:
Since upgrading to 10.0.27, the exact same request returns:
Important details
The email address is correctly retrieved by my application.
The
Session-TokenandApp-Tokenare valid.The API user has the required rights on tickets.
I also tested the operation directly through the GLPI web interface while logged in as the same API user, and the operation works correctly.
I also tested with an Administrator profile, with the same result through the API.
Therefore, this does not appear to be a simple missing permission in the user's profile.
External requester
The requester is intentionally an external person and does not necessarily exist as a GLPI user.
Therefore:
is intentional, while:
contains the actual requester email address.
This workflow was working correctly before upgrading to 10.0.27.
Possible regression
I noticed PR #22428:
#22428
which changes the API rights validation and mentions cases where the API can return:
while the corresponding operation works through the web interface.
My issue appears to be very similar, but with
Ticket_User/ ticket requester management rather thanItem_SoftwareVersion.Could the rights validation introduced/changed in this area also affect the creation of a
Ticket_Userwith:?
Expected behavior
The API should allow an authorized user to add an external requester to a ticket using
alternative_email, as it did before GLPI 10.0.27.Actual behavior
The API returns:
even though:
Version
POST /Ticket_Userusers_id = 0)Could you please confirm whether this is an intentional change in the rights validation for
Ticket_User, or a regression in 10.0.27?Relevant log output
Page URL
No response
Steps To reproduce
No response
Your GLPI setup information
No response
Anything else?
No response