diff --git a/CHANGELOG.md b/CHANGELOG.md index 8c48cc26..0e7924f2 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -19,6 +19,7 @@ and this project adheres to [Semantic Versioning](http://semver.org/). - Fix dependency conflict with GLPI core by no longer vendoring symfony/deprecation-contracts and symfony/polyfill-ctype. - Fix default field values not being applied when fields are empty on creation - Fix mandatory fields blocking automated item creation +- Fix ticket observers being able to edit and save additional fields they are not allowed to modify ## [1.24.5] - 2026-09-11 diff --git a/inc/container.class.php b/inc/container.class.php index 45afb6ed..3727ebee 100644 --- a/inc/container.class.php +++ b/inc/container.class.php @@ -1900,6 +1900,19 @@ public static function preItemUpdate(CommonDBTM $item) { self::preItem($item); if (array_key_exists('_plugin_fields_data', $item->input)) { + // Only save plugin fields if the user can update this specific item. + // Automated contexts (cron jobs, API without active profile) bypass this check. + if ( + isset($_SESSION['glpiactiveprofile']['id']) + && $_SESSION['glpiactiveprofile']['id'] != null + && $item instanceof CommonITILObject + && Session::getCurrentInterface() === 'helpdesk' + && !$item->canRequesterUpdateItem() + ) { + unset($item->input['_plugin_fields_data']); + return true; + } + $data = $item->input['_plugin_fields_data']; $data['itemtype'] = $item::class; $data['entities_id'] = $item->isEntityAssign() ? $item->getEntityID() : 0; diff --git a/inc/field.class.php b/inc/field.class.php index fc5f8983..8c0c3bbf 100644 --- a/inc/field.class.php +++ b/inc/field.class.php @@ -891,7 +891,7 @@ public static function showForTabContainer($c_id, $item) return null; } - $canedit = $right > READ; + $canedit = $right > READ && ($item->isNewItem() || $item->canUpdateItem()); //get fields for this container $field_obj = new self(); @@ -1210,7 +1210,7 @@ public static function prepareHtmlFields( return null; } - $canedit = $right > READ; + $canedit = $right > READ && ($item->isNewItem() || $item->canUpdateItem()); // Fill status overrides if needed if (in_array($item->getType(), PluginFieldsStatusOverride::getStatusItemtypes())) {