Ad Widget

Collapse

Why guest users may edit trigger comments?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Mox
    Member
    • Sep 2009
    • 90

    #1

    Why guest users may edit trigger comments?

    Now, in Zabbix 1.8.3, guest users can edit trigger comment.
    Is it feature or bug?

    I mean that it is not necessary. IMHO only administrators should edit trigger comments.
    Last edited by Mox; 21-09-2010, 15:18. Reason: some grammatic changes
  • Mox
    Member
    • Sep 2009
    • 90

    #2
    any ideas?

    Comment

    • richlv
      Senior Member
      Zabbix Certified Trainer
      Zabbix Certified SpecialistZabbix Certified Professional
      • Oct 2005
      • 3112

      #3
      if true, it definitely is a bug. please, report on the tracker
      Zabbix 3.0 Network Monitoring book

      Comment

      • Mox
        Member
        • Sep 2009
        • 90

        #4
        Originally posted by richlv
        if true, it definitely is a bug. please, report on the tracker
        excuse me, where can I find similar tracker?

        Comment

        • richlv
          Senior Member
          Zabbix Certified Trainer
          Zabbix Certified SpecialistZabbix Certified Professional
          • Oct 2005
          • 3112

          #5
          not sure about similarity, but zabbix bugtracker is located at https://support.zabbix.com
          Zabbix 3.0 Network Monitoring book

          Comment

          • Mox
            Member
            • Sep 2009
            • 90

            #6
            thank you very much!

            Comment

            • James Wells
              Senior Member
              • Jun 2005
              • 664

              #7
              Greetings,
              Originally posted by Mox
              Now, in Zabbix 1.8.3, guest users can edit trigger comment.
              Yes and no. They can edit alert comments, but not trigger comments. When a trigger fires, an alert is generated. During this process the trigger comments are copied to the alert comments. Anyone can append to the alert comments, but they cannot change the trigger comments as there is no mechanism for returning the data back to the trigger than caused the alert.

              I mean that it is not necessary. IMHO only administrators should edit trigger comments.
              This was originally put in to allow people working on the alert to communicate directly through the Zabbix UI by commenting directly on the alert.
              Unofficial Zabbix Developer

              Comment

              • richlv
                Senior Member
                Zabbix Certified Trainer
                Zabbix Certified SpecialistZabbix Certified Professional
                • Oct 2005
                • 3112

                #8
                unfortunately, not really

                if i got you correctly, you are talking about acknowledges - what is happening instead, guest (or most likely also any other user) with r/o access to a host can now edit trigger comments, which get saved to trigger configuration. a bug that should be fixed, of course.
                Zabbix 3.0 Network Monitoring book

                Comment

                • Mox
                  Member
                  • Sep 2009
                  • 90

                  #9
                  richlv right. I`m talking about trigger comments (monitoring->triggers->comments:add/show).
                  Not about acknowledges (monitoring->events->ack:yes/no).
                  Or I understand you incorrectly (I don`t understand what is `alert comments`).
                  Last edited by Mox; 27-09-2010, 22:19.

                  Comment

                  • James Wells
                    Senior Member
                    • Jun 2005
                    • 664

                    #10
                    Originally posted by richlv
                    if i got you correctly, you are talking about acknowledges
                    Nope, was talking about the alert comments. When you go to the trigger status page, the far right column (Comments) used to be read not from the triggers table, but from the alerts table. And it used to work the way I described above.

                    Acknowledges are yet another table and the comments there were meant for one purpose only to silence actions, while keeping an auditable log of who ack'd an alert and when.

                    what is happening instead, guest (or most likely also any other user) with r/o access to a host can now edit trigger comments, which get saved to trigger configuration. a bug that should be fixed, of course
                    Yeah, I found that out after reading your reply. The only good thing about the bug is that it does not propagate the edits up the tree or to other branches. As such it is easy to repair the damage by re-pushing the trigger configuration from the template. But, yes that bug needs to be fixed.
                    Unofficial Zabbix Developer

                    Comment

                    • richlv
                      Senior Member
                      Zabbix Certified Trainer
                      Zabbix Certified SpecialistZabbix Certified Professional
                      • Oct 2005
                      • 3112

                      #11
                      Originally posted by James Wells
                      Nope, was talking about the alert comments. When you go to the trigger status page, the far right column (Comments) used to be read not from the triggers table, but from the alerts table. And it used to work the way I described above.
                      hmm. are you sure ? alerts table is used to store actual alerts, which are not really visible in the triggers table, and checking schemas of several zabbix versions i can't find any indications that it's been otherwise before
                      Zabbix 3.0 Network Monitoring book

                      Comment

                      • Mox
                        Member
                        • Sep 2009
                        • 90

                        #12
                        resolved

                        Comment

                        Working...