Skip to content

GLPI 10.0.27 – API Ticket_User returns ERROR_GLPI_ADD for external reques #25591

Description

@xseth03

Code of Conduct

  • I agree to follow this project's Code of Conduct

Disable plugins

  • I reproduce the issue with all plugins disabled

Is there an existing issue for this?

  • I have searched the existing issues

Version

10.0.27

Bug description

Since upgrading to GLPI 10.0.27, I have an issue when using the REST API to add an external requester to a ticket.

My use case is to assign an external requester to a ticket using an email address that is not necessarily associated with a GLPI user.

Before upgrading to GLPI 10.0.27, the following API request worked correctly:

{
  "input": {
    "tickets_id": 12345,
    "users_id": 0,
    "type": 1,
    "use_notification": 1,
    "alternative_email": "external.user@example.com"
  }
}

The API endpoint is:

POST /apirest.php/Ticket_User

Since upgrading to 10.0.27, the exact same request returns:

HTTP CODE: 400

["ERROR_GLPI_ADD","You don't have permission to perform this action."]

Important details

The email address is correctly retrieved by my application.

The Session-Token and App-Token are valid.

The API user has the required rights on tickets.

I also tested the operation directly through the GLPI web interface while logged in as the same API user, and the operation works correctly.

I also tested with an Administrator profile, with the same result through the API.

Therefore, this does not appear to be a simple missing permission in the user's profile.

External requester

The requester is intentionally an external person and does not necessarily exist as a GLPI user.

Therefore:

"users_id": 0

is intentional, while:

"alternative_email": "external.user@example.com"

contains the actual requester email address.

This workflow was working correctly before upgrading to 10.0.27.

Possible regression

I noticed PR #22428:

#22428

which changes the API rights validation and mentions cases where the API can return:

ERROR_GLPI_ADD - You don't have permission to perform this action

while the corresponding operation works through the web interface.

My issue appears to be very similar, but with Ticket_User / ticket requester management rather than Item_SoftwareVersion.

Could the rights validation introduced/changed in this area also affect the creation of a Ticket_User with:

"users_id": 0,
"type": 1,
"alternative_email": "..."

?

Expected behavior

The API should allow an authorized user to add an external requester to a ticket using alternative_email, as it did before GLPI 10.0.27.

Actual behavior

The API returns:

ERROR_GLPI_ADD
You don't have permission to perform this action.

even though:

  • the API user has the required ticket permissions;
  • the same user can perform the operation through the web interface;
  • an Administrator profile produces the same result;
  • the email address is valid;
  • the Session-Token and App-Token are valid.

Version

  • GLPI: 10.0.27
  • API: REST API
  • Endpoint: POST /Ticket_User
  • Requester: external user (users_id = 0)
  • Authentication: Session-Token + App-Token

Could you please confirm whether this is an intentional change in the rights validation for Ticket_User, or a regression in 10.0.27?

Relevant log output

Page URL

No response

Steps To reproduce

No response

Your GLPI setup information

No response

Anything else?

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions