Page 1 of 1

Security

Posted: Tue Nov 03, 2009 6:13 am
by southernmoney
Hi Klemen,

Please consider the following for the new version of Hesk:

1. It is in sometimes form a security point of view as well as the need to forward tickets to colleagues important to know which colleagues are online.

2. It is important to have a build in option to prevent staff from accessing Hesk when they are not at the office. At this stage staff can go to their private computer and copy contact details from the database and abuse it. I know that some may feel it is important for their staff to access Hesk from their homes so the option should at least be available to exclude it.

Best Wishes.

Southern Money

Posted: Tue Nov 03, 2009 11:01 am
by Raven
Hi, I like the idea of a 'Who's online' and maybe in collaberation with this maybe something to stop anyone else editing a ticket if another user already has it open to save duplication etc...

I think the easiest way would be in the manage_users.php file where you could have a .gif (green if logged-in or red if logged out) next to each users name sort of like the old phpBB used to have.

As for a built-in way of making HESK only avail from work, well this has nothing to do with this script, or any other for that matter. Simply block all external access using the main web servers configuration (http.conf / php.ini etc...) - I say this as not all users work from an office all of the time and this kind of detracts from the main use of HESK. I mean if you trust someone enough to give them access to HESK and have them provide technical support to your customers then why block them from using HESK - seems daft as any employee is bound by the data protection act anyway!

Anyway, just my thoughts on the subject :)