-
Type:
Bug
-
Status: Closed
-
Priority:
Medium
-
Resolution: Done
-
Component/s: BenAdmin
-
Labels:None
-
Module:BenAdmin - Security
-
Reported by:Support
-
Item State:Production Complete - Closed
-
Issue Importance:Must Have
URL:
https://wt-stage.harbinger.in/Assets/Temp/d4b28f08-dfb5-4923-850c-c53bac2383f6.pdf
Description:
login with employee credentials and in confirmation statement there is
Option to export pdf. This link can be directly accessed and viewed from different machines without Credentials.
Resolution:
Restrict all post login pages from getting accessed directly.
Authorization of the user specific resource must be implemented and publicly they should not be accessible
Field | Original Value | New Value |
---|---|---|
Assignee | Vijayendra Shinde [ ID10506 ] |
Status | Open [ 1 ] | In Development [ 10007 ] |
Item State | Parent values: Development(10200)Level 1 values: In Progress(10206) | Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209) |
Item State | Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209) | Parent values: LB QA(10201) |
Assignee | Vijayendra Shinde [ ID10506 ] | Deepali Tidke [ deepalit ] |
Item State | Parent values: LB QA(10201) | Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) |
Status | In Development [ 10007 ] | Local Testing [ 10200 ] |
Status | Local Testing [ 10200 ] | Reopen in Local [ 10018 ] |
Item State | Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) | Parent values: Development(10200) |
Attachment | 07_18_2016_15_39_20_921_3864_2.txt [ 22103 ] |
Assignee | Deepali Tidke [ deepalit ] | Vijayendra Shinde [ ID10506 ] |
Status | Reopen in Local [ 10018 ] | In Development [ 10007 ] |
Item State | Parent values: Development(10200) | Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209) |
Assignee | Vijayendra Shinde [ ID10506 ] | Kumar Chhajed [ kumar.chhajed ] |
Item State | Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209) | Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) |
Assignee | Kumar Chhajed [ kumar.chhajed ] | Sachin Hingole [ sachin.hingole ] |
Status | In Development [ 10007 ] | Local Testing [ 10200 ] |
Item State | Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) | Parent values: LB QA(10201)Level 1 values: In Testing(10210) |
Status | Local Testing [ 10200 ] | Reopen in Local [ 10018 ] |
Status | Reopen in Local [ 10018 ] | In Development [ 10007 ] |
Status | In Development [ 10007 ] | Local Testing [ 10200 ] |
Item State | Parent values: LB QA(10201)Level 1 values: In Testing(10210) | Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213) |
Stage Due Date | 25/Jul/16 [ 2016-07-25 ] |
Production Due Date | 26/Jul/2016 |
Item State | Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213) | Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217) |
Status | Local Testing [ 10200 ] | Stage Testing [ 10201 ] |
Status | Stage Testing [ 10201 ] | Production Testing [ 10202 ] |
Developer | Kumar Chhajed [ kumar.chhajed ] |
Item State | Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217) | Parent values: Production QA(10203)Level 1 values: Production Deployed(10221) |
Item State | Parent values: Production QA(10203)Level 1 values: Production Deployed(10221) | Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217) |
Item State | Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217) | Parent values: Production QA(10203)Level 1 values: In Testing(10218) |
Resolution | Fixed [ 1 ] | |
Status | Production Testing [ 10202 ] | Production Complete [ 10028 ] |
Item State | Parent values: Production QA(10203)Level 1 values: In Testing(10218) | Parent values: Production Complete(10222)Level 1 values: Closed(10223) |
Status | Production Complete [ 10028 ] | Closed [ 6 ] |
Transition | Time In Source Status | Execution Times |
---|
|
17s | 1 |
|
1h 25m | 2 |
|
1h 30m | 2 |
|
6d 1h 51m | 3 |
|
5d 20h 54m | 1 |
|
2s | 1 |
|
7d 9h 20m | 1 |
|
14s | 1 |
Affected files:
/trunk/WORKTERRAweb/Web/Web Projects/BenAdmin/Areas/ACA/Views/ACA/ACAAnalytics/PCORIReport.cshtml
/trunk/WORKTERRAweb/Web/Web Projects/BenAdmin/Areas/UserDetails/Views/UserDetails/EnrollmentSummary/EnrollmentSummary.cshtml
Newly added:
SharedFunctionWebTier/SharedFunctionWebTier/Views/Shared/NotFound.cshtml
SharedFunctionWebTier/SharedFunctionWebTier/Views/Shared/NotFound.generated.cs
Web Projects/WORKTERRA/ReportViewer/ViewReport.aspx.cs