Page 1 of 1

admin_search_lead.php issue

PostPosted: Sun May 20, 2012 2:57 am
by rrb555
Hi,

Seems like User Group campaign list restrictions to search queries is not working?

We can still search other users that are on the other User

http://www.vicidial.org/VICIDIALmantis/view.php?id=575

Re: admin_search_lead.php issue

PostPosted: Sun May 20, 2012 9:20 pm
by williamconley
Exactly what did you search for on what page that showed results that should not have been shown?

When you search for a lead, you do not find "users", you find leads.

Be very specific. Something like "I put XXXXXXXXXX in the Phone field and pressed submit on admin_search_lead.php and I got 5 resulting leads and 2 of those leads were in campaigns that I should not have been able to see according to the Admin user group settings". Then list your Admin User Group settings in all related areas for confirmation.

But since "users" are not returned when searching for "Leads" in "admin search lead" ... I can't really help based on your statement.

Re: admin_search_lead.php issue

PostPosted: Mon May 21, 2012 8:50 am
by rrb555
Thank you for the reply William

I am trying to check the admin_search_lead.php,
USER GROUPS
User Group: TESTCAMP
Allowed Campaigns: TESTCAMP
Agent Status Viewable Groups: TESTCAMP
Allowed User Groups: TESTCAMP
Agents: AgentA01, AgentA02
Username: SupervisorA
Level: 8
Admin Interface Options: all options enabled

When searching under Lists > Search for A Lead > Phone > XXXXXXX228
I've got 1 result but surprisingly that agent dialed that number doesn't belong to my user group. I can see the last agent dialed that number is AgentB01. Clicking to that lead ID, I can see that my agent "AgentA01" and then the other agent "AgentB01" call logs,agent closer records and even recordings for the leads.

Now knowing that AgentB01 exist, I tried searching under Lists > Search for a Lead > Users > AgentB01 and could see all the leads dialed by AgentB01.

Re: admin_search_lead.php issue

PostPosted: Mon May 21, 2012 12:16 pm
by rrb555
Update:

since like the primary security of the admin_search_lead.php is to check on to what campaign the list id (or allowed campaigns) is set to. so if i manual dial and its already on the system to which also assigned to other User Group, the Supervisor can not view that lead

anyone who knows how to make the security by Allowed user groups?