From ac697a6134c025dcf8dc961279ed776dbcbd7806 Mon Sep 17 00:00:00 2001 From: Herafia Date: Tue, 29 Sep 2026 12:20:17 +0200 Subject: [PATCH 1/3] Fix ticket observer can edit --- inc/container.class.php | 11 +++++++++++ inc/field.class.php | 4 ++-- 2 files changed, 13 insertions(+), 2 deletions(-) diff --git a/inc/container.class.php b/inc/container.class.php index 45afb6ed..573ebae0 100644 --- a/inc/container.class.php +++ b/inc/container.class.php @@ -1900,6 +1900,17 @@ public static function preItemUpdate(CommonDBTM $item) { self::preItem($item); if (array_key_exists('_plugin_fields_data', $item->input)) { + // Only save plugin fields if the user can update this specific item. + // Automated contexts (cron jobs, API without active profile) bypass this check. + if ( + isset($_SESSION['glpiactiveprofile']['id']) + && $_SESSION['glpiactiveprofile']['id'] !== null + && !$item->canUpdateItem() + ) { + unset($item->input['_plugin_fields_data']); + return true; + } + $data = $item->input['_plugin_fields_data']; $data['itemtype'] = $item::class; $data['entities_id'] = $item->isEntityAssign() ? $item->getEntityID() : 0; diff --git a/inc/field.class.php b/inc/field.class.php index fc5f8983..8c0c3bbf 100644 --- a/inc/field.class.php +++ b/inc/field.class.php @@ -891,7 +891,7 @@ public static function showForTabContainer($c_id, $item) return null; } - $canedit = $right > READ; + $canedit = $right > READ && ($item->isNewItem() || $item->canUpdateItem()); //get fields for this container $field_obj = new self(); @@ -1210,7 +1210,7 @@ public static function prepareHtmlFields( return null; } - $canedit = $right > READ; + $canedit = $right > READ && ($item->isNewItem() || $item->canUpdateItem()); // Fill status overrides if needed if (in_array($item->getType(), PluginFieldsStatusOverride::getStatusItemtypes())) { From c8daefffa4186fec9d55b022ec747edfb61cac7a Mon Sep 17 00:00:00 2001 From: Herafia Date: Wed, 30 Sep 2026 09:35:29 +0200 Subject: [PATCH 2/3] fix CI --- inc/container.class.php | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/inc/container.class.php b/inc/container.class.php index 573ebae0..3727ebee 100644 --- a/inc/container.class.php +++ b/inc/container.class.php @@ -1904,8 +1904,10 @@ public static function preItemUpdate(CommonDBTM $item) // Automated contexts (cron jobs, API without active profile) bypass this check. if ( isset($_SESSION['glpiactiveprofile']['id']) - && $_SESSION['glpiactiveprofile']['id'] !== null - && !$item->canUpdateItem() + && $_SESSION['glpiactiveprofile']['id'] != null + && $item instanceof CommonITILObject + && Session::getCurrentInterface() === 'helpdesk' + && !$item->canRequesterUpdateItem() ) { unset($item->input['_plugin_fields_data']); return true; From bd189b5e23a9798d981ceacbce8d66396aab6317 Mon Sep 17 00:00:00 2001 From: Herafia Date: Wed, 30 Sep 2026 09:50:52 +0200 Subject: [PATCH 3/3] changelog --- CHANGELOG.md | 1 + 1 file changed, 1 insertion(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 8c48cc26..0e7924f2 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -19,6 +19,7 @@ and this project adheres to [Semantic Versioning](http://semver.org/). - Fix dependency conflict with GLPI core by no longer vendoring symfony/deprecation-contracts and symfony/polyfill-ctype. - Fix default field values not being applied when fields are empty on creation - Fix mandatory fields blocking automated item creation +- Fix ticket observers being able to edit and save additional fields they are not allowed to modify ## [1.24.5] - 2026-09-11