/usr/share/otrs/Kernel/Modules/AgentTicketWatcher.pm is in otrs2 5.0.7-1.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 | # --
# Copyright (C) 2001-2016 OTRS AG, http://otrs.com/
# --
# This software comes with ABSOLUTELY NO WARRANTY. For details, see
# the enclosed file COPYING for license information (AGPL). If you
# did not receive this file, see http://www.gnu.org/licenses/agpl.txt.
# --
package Kernel::Modules::AgentTicketWatcher;
use strict;
use warnings;
our $ObjectManagerDisabled = 1;
use Kernel::System::VariableCheck qw(:all);
sub new {
my ( $Type, %Param ) = @_;
# allocate new hash for object
my $Self = {%Param};
bless( $Self, $Type );
return $Self;
}
sub Run {
my ( $Self, %Param ) = @_;
# get needed objects
my $ConfigObject = $Kernel::OM->Get('Kernel::Config');
my $LayoutObject = $Kernel::OM->Get('Kernel::Output::HTML::Layout');
# ------------------------------------------------------------ #
# check if feature is active
# ------------------------------------------------------------ #
if ( !$ConfigObject->Get('Ticket::Watcher') ) {
return $LayoutObject->ErrorScreen(
Message => 'Feature is not active',
);
}
# ------------------------------------------------------------ #
# check access
# ------------------------------------------------------------ #
my @Groups;
if ( $ConfigObject->Get('Ticket::WatcherGroup') ) {
@Groups = @{ $ConfigObject->Get('Ticket::WatcherGroup') };
}
my $Access = 1;
if (@Groups) {
$Access = 0;
for my $Group (@Groups) {
if ( $LayoutObject->{"UserIsGroup[$Group]"} eq 'Yes' ) {
$Access = 1;
}
}
}
if ( !$Access ) {
return $Self->{Layout}->NoPermission();
}
# get ACL restrictions
my %PossibleActions = ( 1 => $Self->{Action} );
# get ticket object
my $TicketObject = $Kernel::OM->Get('Kernel::System::Ticket');
my $ACL = $TicketObject->TicketAcl(
Data => \%PossibleActions,
Action => $Self->{Action},
TicketID => $Self->{TicketID},
ReturnType => 'Action',
ReturnSubType => '-',
UserID => $Self->{UserID},
);
my %AclAction = $TicketObject->TicketAclActionData();
# check if ACL restrictions exist
if ( $ACL || IsHashRefWithData( \%AclAction ) ) {
my %AclActionLookup = reverse %AclAction;
# show error screen if ACL prohibits this action
if ( !$AclActionLookup{ $Self->{Action} } ) {
return $LayoutObject->NoPermission( WithHeader => 'yes' );
}
}
# ------------------------------------------------------------ #
# subscribe a ticket
# ------------------------------------------------------------ #
if ( $Self->{Subaction} eq 'Subscribe' ) {
# challenge token check for write action
$LayoutObject->ChallengeTokenCheck();
# Checks if the user has permissions to see the ticket.
# This is needed because watching grants ro permissions (depending on configuration).
my $Access = $TicketObject->TicketPermission(
Type => 'ro',
TicketID => $Self->{TicketID},
UserID => $Self->{UserID},
);
if ( !$Access ) {
return $LayoutObject->NoPermission( WithHeader => 'yes' );
}
# set subscribe
my $Subscribe = $TicketObject->TicketWatchSubscribe(
TicketID => $Self->{TicketID},
WatchUserID => $Self->{UserID},
UserID => $Self->{UserID},
);
if ( !$Subscribe ) {
return $LayoutObject->ErrorScreen();
}
# redirect
return $LayoutObject->Redirect(
OP => "Action=AgentTicketZoom;TicketID=$Self->{TicketID}",
);
}
# ------------------------------------------------------------ #
# unsubscribe a ticket
# ------------------------------------------------------------ #
elsif ( $Self->{Subaction} eq 'Unsubscribe' ) {
# challenge token check for write action
$LayoutObject->ChallengeTokenCheck();
# We don't need a permission check here as we will remove
# permissions by unsubscribing.
my $Unsubscribe = $TicketObject->TicketWatchUnsubscribe(
TicketID => $Self->{TicketID},
WatchUserID => $Self->{UserID},
UserID => $Self->{UserID},
);
if ( !$Unsubscribe ) {
return $LayoutObject->ErrorScreen();
}
# redirect
# checks if the user has permissions to see the ticket
my $Access = $TicketObject->TicketPermission(
Type => 'ro',
TicketID => $Self->{TicketID},
UserID => $Self->{UserID},
);
if ( !$Access ) {
# generate output
return $LayoutObject->Redirect(
OP => $Self->{LastScreenOverview} || 'Action=AgentDashboard',
);
}
return $LayoutObject->Redirect(
OP => "Action=AgentTicketZoom;TicketID=$Self->{TicketID}",
);
}
$LayoutObject->ErrorScreen( Message => 'Invalid subaction' );
}
1;
|