Uploaded image for project: 'Project Simple'
  1. Project Simple
  2. ST-100

Old password encryption at client side on change password page

    Details

    • Type: Enhancement
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
      None
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Sprint:
      ST Sprint 1

      Description

      Refer parent ticket for this issue : https://workterra.atlassian.net/browse/ST-84

      1. Password needs to be encrypt at client side for security purpose. It'll decrypt at server side for authentication. In short, we are transmitting old password in encrypted format.

        Attachments

          Issue Links

            Activity

            Hide
            niteen.surwase Niteen Surwase (Inactive) added a comment -

            Page :
            Change Password (Old Password Field)

            Description :

            Only encryption and decryption for old password is implemented in this patch.

            When we enter all fields and hit save button then it encrypts old password at client side and transmit it to server. When it receives at controller, using same algorithm it is decrypted. While transmitting the old password it is in encrypted format for security.

            Show
            niteen.surwase Niteen Surwase (Inactive) added a comment - Page : Change Password (Old Password Field) Description : Only encryption and decryption for old password is implemented in this patch. When we enter all fields and hit save button then it encrypts old password at client side and transmit it to server. When it receives at controller, using same algorithm it is decrypted. While transmitting the old password it is in encrypted format for security.
            Hide
            shubhankar Shubhankar Joshi (Inactive) added a comment -

            This feature has been tested in the local environment and is working as expected. The Passwords are being sent in the encrypted form to the server from the client.

            Show
            shubhankar Shubhankar Joshi (Inactive) added a comment - This feature has been tested in the local environment and is working as expected. The Passwords are being sent in the encrypted form to the server from the client.
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Hi please implement old password field for verification

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Hi please implement old password field for verification
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Hi Niteen Surwase The old password is sent from Client to server in clear text

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Hi Niteen Surwase The old password is sent from Client to server in clear text
            Hide
            niteen.surwase Niteen Surwase (Inactive) added a comment - - edited

            Hi Zeeshan Chishty,

            Old password is going in encrypted format. You have not verified for old Password Field, Please check it again for Old Password Field not for New Password/Confirm Password field. I have verified it and it is in encrypted format.

            To enable Old Password field please refer parent ticket ST-84

            Show
            niteen.surwase Niteen Surwase (Inactive) added a comment - - edited Hi Zeeshan Chishty , Old password is going in encrypted format. You have not verified for old Password Field , Please check it again for Old Password Field not for New Password/Confirm Password field. I have verified it and it is in encrypted format. To enable Old Password field please refer parent ticket ST-84
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Hi Niteen SurwaseNiteen,

            I have added the screenshot. If you want more proof Please come at my desk I will show you the steps for it.

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Hi Niteen Surwase Niteen, I have added the screenshot. If you want more proof Please come at my desk I will show you the steps for it.
            Hide
            niteen.surwase Niteen Surwase (Inactive) added a comment - - edited

            Reverting back this implementation as encryption is not necessary But temporary moving on production. After that it get removed through all branches.

            Show
            niteen.surwase Niteen Surwase (Inactive) added a comment - - edited Reverting back this implementation as encryption is not necessary But temporary moving on production. After that it get removed through all branches.
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Hi Rakesh Roy Please take necessary decision on this ticket as the changes are now reverted and I am not sure what should be the status.

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Hi Rakesh Roy Please take necessary decision on this ticket as the changes are now reverted and I am not sure what should be the status.
            Hide
            deepalit Deepali Tidke (Inactive) added a comment -

            This has been completed on production hence it can be closed, discussed with Niteen.

            Show
            deepalit Deepali Tidke (Inactive) added a comment - This has been completed on production hence it can be closed, discussed with Niteen.

              People

              Assignee:
              deepalit Deepali Tidke (Inactive)
              Reporter:
              niteen.surwase Niteen Surwase (Inactive)
              Developer:
              Niteen Surwase (Inactive)
              QA:
              Shubhankar Joshi (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: