Uploaded image for project: 'New Features 2017'
  1. New Features 2017
  2. NF-2334

All Company- Employee Login - URL parameters - Security - URL parameters in all the SSM pages,reports are displayed in plain text.

    Details

    • Type: Bug
    • Status: Closed
    • Priority: High
    • Resolution: Bug Fixed
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: UI Refresh
    • Labels:
      None
    • Environment:
      Pre Production
    • Bug Type:
      Functional
    • Bug Severity:
      Medium
    • Level:
      Employee
    • Module:
      BenAdmin - Security
    • Reported by:
      Harbinger
    • Company:
      All Clients/Multiple Clients
    • Item State:
      Stage QA - Production Deployment on Hold
    • Issue Importance:
      Q2

      Description

      All Company- Employee Login - URL parameters - Security - URL parameter values in all the SSM pages,reports are displayed in plain text.

      As observed all the URL parameter values are displayed in plain english text and can be vulnerable for security breach.

      This can be generic issue and may exist for Admin,Partners,SA user roles too.

      CC : Vijayendra ShindeSachin HingoleRakesh RoyHrishikesh DeshpandeRohan J KhandaveSamir

        Attachments

        1. CCSF_URLData_notEncrypted.jpg
          222 kB
          Prasad Pise
        2. EmpBen.jpg
          99 kB
          Prasad Pise
        3. ParameterURL.jpg
          180 kB
          Prasad Pise

          Issue Links

            Activity

            Hide
            komal.barde Komal Barde (Inactive) added a comment -

            List of modified files:

            • /branches/UiRefresh-LB/Web/Web Projects/BenAdmin/Areas/UserDetails/Controllers/EmployeeBeneficiary/EmployeeBeneficiaryController.cs
            • /branches/UiRefresh-LB/Web/Web Projects/BenAdmin/Areas/UserDetails/Controllers/EnrollNow/EnrollNowController.cs
            • /branches/UiRefresh-LB/Web/Web Projects/BenAdmin/Areas/UserDetails/Models/EnrollNow/EnrollNowPVModel.cs
            • /branches/UiRefresh-LB/Web/Web Projects/BenAdmin/Areas/UserDetails/Views/UserDetails/EmployeeBeneficiary/EmployeeBeneficiary.cshtml
            Show
            komal.barde Komal Barde (Inactive) added a comment - List of modified files : /branches/UiRefresh-LB/Web/Web Projects/BenAdmin/Areas/UserDetails/Controllers/EmployeeBeneficiary/EmployeeBeneficiaryController.cs /branches/UiRefresh-LB/Web/Web Projects/BenAdmin/Areas/UserDetails/Controllers/EnrollNow/EnrollNowController.cs /branches/UiRefresh-LB/Web/Web Projects/BenAdmin/Areas/UserDetails/Models/EnrollNow/EnrollNowPVModel.cs /branches/UiRefresh-LB/Web/Web Projects/BenAdmin/Areas/UserDetails/Views/UserDetails/EmployeeBeneficiary/EmployeeBeneficiary.cshtml
            Hide
            prasadp Prasad Pise (Inactive) added a comment -

            Hi Komal Barde

            I have verified the fixes for following changes on Codemap
            1. PCP Pop up scenario
            2. Edit/Update Employee Beneficiary request
            3. Add another relation ship for beneficiary

            I have observed following issue:
            On Beneficiary page, Relationship Name's encrypted value is getting displayed on UI.
            This issue occurs when employee try to Add/Edit the beneficiary from employee beneficiary page.
            PFA screenshot.

            CC Vijayendra Shinde

            Show
            prasadp Prasad Pise (Inactive) added a comment - Hi Komal Barde I have verified the fixes for following changes on Codemap 1. PCP Pop up scenario 2. Edit/Update Employee Beneficiary request 3. Add another relation ship for beneficiary I have observed following issue: On Beneficiary page, Relationship Name's encrypted value is getting displayed on UI. This issue occurs when employee try to Add/Edit the beneficiary from employee beneficiary page. PFA screenshot. CC Vijayendra Shinde
            Hide
            pratap.patil Pratap Patil (Inactive) added a comment -

            Hello Prasad Pise ,

            The beneficiary relationship name issue is fixed and deployed on CodeMap . Please verify it .

            Thanks,
            Pratap

            Show
            pratap.patil Pratap Patil (Inactive) added a comment - Hello Prasad Pise , The beneficiary relationship name issue is fixed and deployed on CodeMap . Please verify it . Thanks, Pratap
            Hide
            prasadp Prasad Pise (Inactive) added a comment -

            HI Pratap Patil

            Beneficiary relationship name issue is resolved on Codemap. As observed, the relationship name is displayed in plain english text on Beneficiary Page and Beneficiary reports.

            Thanks

            • Prasad
            Show
            prasadp Prasad Pise (Inactive) added a comment - HI Pratap Patil Beneficiary relationship name issue is resolved on Codemap. As observed, the relationship name is displayed in plain english text on Beneficiary Page and Beneficiary reports. Thanks Prasad
            Hide
            prasadp Prasad Pise (Inactive) added a comment -

            HI Pratap Patil
            Beneficiary relationship name issue is resolved on PreProd environment. Now,Relationship name is displayed in plain english text on Beneficiary Page and Beneficiary reports.

            Thanks
            -Prasad

            Show
            prasadp Prasad Pise (Inactive) added a comment - HI Pratap Patil Beneficiary relationship name issue is resolved on PreProd environment. Now,Relationship name is displayed in plain english text on Beneficiary Page and Beneficiary reports. Thanks -Prasad

              People

              Assignee:
              prasadp Prasad Pise (Inactive)
              Reporter:
              prasadp Prasad Pise (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 26.5h
                  26.5h