Comments and Work Notes ACL not working. Work notes showing for end users

jlt
Kilo Contributor

It was recently reported that our end users are seeing work notes made by ITIL roled users in the comments and work notes and/or Activities (filtered) fields on forms even though there is an ACL that limits read access to task.work_notes to users with the role ITIL.   If I add the field "work note" to the Self Service View, it appropriately is hidden from the non roled users view so the ACL is hiding the work notes field, but any work notes made previously still show in these journaled lists.  

I know this was not always the case and am unsure when this problem emerged for us.  

Can anyone tell me how to hide the worknotes in the journals lists from non-roled users but still allow them to create/read additional comments?

14 REPLIES 14

The screen shot shows a Write ACL. Can you double check you have a Read ACL?


jlt
Kilo Contributor

Ooops wrong one.. yes I have read one


find_real_file.png


Are there any other Read ACL's on work_notes? Doesn't make sense, something is allowing access.


jlt
Kilo Contributor

Yes I agree.. it doesn't make sense... nope no other ACL's on worknotes


find_real_file.png


You can impersonate a Self Service user and see work notes field? or just the work notes in activity?