Uploaded image for project: 'Project Simple'
  1. Project Simple
  2. ST-251

Report query string parameterization

    Details

    • Type: Enhancement
    • Status: Closed
    • Priority: Critical
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
      None
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Issue Importance:
      Must Have

      Description

      All parameters are visible in browser when user view report.

      Resolution:
      We should encrypt report query string parameters so that user should not be able to manipulate reports.

        Attachments

          Activity

          vijayendra Vijayendra Shinde (Inactive) created issue -
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Field Original Value New Value
          Assignee Vijayendra Shinde [ ID10506 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Status New Request [ 10029 ] Pending for Approval [ 10002 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Status Pending for Approval [ 10002 ] Approved for Development [ 10003 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Status Approved for Development [ 10003 ] In Development [ 10007 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Component/s BenAdmin [ 10100 ]
          Issue Importance Must Have [ 11800 ]
          Item State Parent values: Development(10200)Level 1 values: In Progress(10206)
          Module Parent values: BenAdmin(10100) Parent values: BenAdmin(10100)Level 1 values: Security(10112)
          Priority Medium [ 3 ] Highest [ 1 ]
          Hide
          vijayendra Vijayendra Shinde (Inactive) added a comment -

          We are working on encrypting parameters of Reports.

          Show
          vijayendra Vijayendra Shinde (Inactive) added a comment - We are working on encrypting parameters of Reports.
          Hide
          vijayendra Vijayendra Shinde (Inactive) added a comment -

          Affected Files:

          SharedFunctionWebTier/SharedFunctionWebTier/Views/Shared/_WORKTERRALayout.cshtml
          SharedFunctionWebTier/SharedFunctionWebTier/Views/Shared/_WORKTERRALayout.generated.cs
          Web Projects/BenAdmin/Scripts/WORKTERRAShared.js
          Web Projects/WORKTERRA/ReportViewer/ViewReport.aspx.cs

          Show
          vijayendra Vijayendra Shinde (Inactive) added a comment - Affected Files: SharedFunctionWebTier/SharedFunctionWebTier/Views/Shared/_WORKTERRALayout.cshtml SharedFunctionWebTier/SharedFunctionWebTier/Views/Shared/_WORKTERRALayout.generated.cs Web Projects/BenAdmin/Scripts/WORKTERRAShared.js Web Projects/WORKTERRA/ReportViewer/ViewReport.aspx.cs
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Developer Vijayendra Shinde [ ID10506 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Assignee Vijayendra Shinde [ ID10506 ] Deepali Tidke [ deepalit ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Item State Parent values: Development(10200)Level 1 values: In Progress(10206) Parent values: LB QA(10201)
          deepalit Deepali Tidke (Inactive) made changes -
          Status In Development [ 10007 ] Local Testing [ 10200 ]
          gokul.sonawane Gokul Sonawane (Inactive) made changes -
          Item State Parent values: LB QA(10201) Parent values: LB QA(10201)Level 1 values: LB Deployed(11600)
          Hide
          deepalit Deepali Tidke (Inactive) added a comment -

          Checked the company level reports on LB from partner, CA and EE login >> on report run >> parameters are encrypted now.

          Sachin Hingole checked the ACA reports on lb and they are also encrypted.

          For Global level reports , encryption is not coming as it not implemented at global level

          Show
          deepalit Deepali Tidke (Inactive) added a comment - Checked the company level reports on LB from partner, CA and EE login >> on report run >> parameters are encrypted now. Sachin Hingole checked the ACA reports on lb and they are also encrypted. For Global level reports , encryption is not coming as it not implemented at global level
          deepalit Deepali Tidke (Inactive) made changes -
          Item State Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213)
          deepalit Deepali Tidke (Inactive) made changes -
          Status Local Testing [ 10200 ] Pending for Stage Approval [ 10300 ]
          deepalit Deepali Tidke (Inactive) made changes -
          Status Pending for Stage Approval [ 10300 ] Approved for Stage [ 10030 ]
          deepalit Deepali Tidke (Inactive) made changes -
          Status Approved for Stage [ 10030 ] Stage Testing [ 10201 ]
          deepalit Deepali Tidke (Inactive) made changes -
          Stage Due Date 25/Jul/16 [ 2016-07-25 ]
          deepalit Deepali Tidke (Inactive) made changes -
          Production Due Date 26/Jul/2016
          Hide
          deepalit Deepali Tidke (Inactive) added a comment -

          Checked the company level reports on stage from partner, CA and EE login >> on report run >> parameters are encrypted now.

          For Global level reports , encryption is not coming as it not implemented at global level

          Sachin Hingole please check ACA level reports on stage.

          Show
          deepalit Deepali Tidke (Inactive) added a comment - Checked the company level reports on stage from partner, CA and EE login >> on report run >> parameters are encrypted now. For Global level reports , encryption is not coming as it not implemented at global level Sachin Hingole please check ACA level reports on stage.
          Hide
          sachin.hingole Sachin Hingole (Inactive) added a comment -

          Verified ACA reports on stage and they are also encrypted.
          Also reports are opening without error.

          Show
          sachin.hingole Sachin Hingole (Inactive) added a comment - Verified ACA reports on stage and they are also encrypted. Also reports are opening without error.
          sachin.hingole Sachin Hingole (Inactive) made changes -
          Item State Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213) Parent values: Stage QA(10202)
          sachin.hingole Sachin Hingole (Inactive) made changes -
          Item State Parent values: Stage QA(10202) Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217)
          rakeshr Rakesh Roy (Inactive) made changes -
          Item State Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217) Parent values: Stage QA(10202)Level 1 values: Production Deployment on Hold(10224)
          satyap Satya made changes -
          Item State Parent values: Stage QA(10202)Level 1 values: Production Deployment on Hold(10224) Parent values: Production QA(10203)Level 1 values: Production Deployed(10221)
          hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
          Assignee Deepali Tidke [ deepalit ] Hrishikesh Deshpande [ hrishikesh.deshpande ]
          rakeshr Rakesh Roy (Inactive) made changes -
          Status Stage Testing [ 10201 ] Pending for Production Approval [ 10301 ]
          rakeshr Rakesh Roy (Inactive) made changes -
          Status Pending for Production Approval [ 10301 ] Approved for production [ 10034 ]
          rakeshr Rakesh Roy (Inactive) made changes -
          Status Approved for production [ 10034 ] Production Testing [ 10202 ]
          rakeshr Rakesh Roy (Inactive) made changes -
          Resolution Fixed [ 1 ]
          Status Production Testing [ 10202 ] Production Complete [ 10028 ]
          rakeshr Rakesh Roy (Inactive) made changes -
          Item State Parent values: Production QA(10203)Level 1 values: Production Deployed(10221) Parent values: Production Complete(10222)Level 1 values: Closed(10223)
          hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
          Status Production Complete [ 10028 ] Closed [ 6 ]
          Transition Time In Source Status Execution Times
          Vijayendra Shinde (Inactive) made transition -
          New Request Pending for Approval
          12s 1
          Vijayendra Shinde (Inactive) made transition -
          Pending for Approval Approved for Development
          1s 1
          Vijayendra Shinde (Inactive) made transition -
          Approved for Development In Development
          1s 1
          Deepali Tidke (Inactive) made transition -
          In Development In LB Testing
          5d 1h 31m 1
          Deepali Tidke (Inactive) made transition -
          In LB Testing Pending for Stage Approval
          1d 18h 22m 1
          Deepali Tidke (Inactive) made transition -
          Pending for Stage Approval Approved for Stage
          2s 1
          Deepali Tidke (Inactive) made transition -
          Approved for Stage Stage Testing
          1s 1
          Rakesh Roy (Inactive) made transition -
          Stage Testing Pending for Production Approval
          56d 21h 24m 1
          Rakesh Roy (Inactive) made transition -
          Pending for Production Approval Approved for production
          4s 1
          Rakesh Roy (Inactive) made transition -
          Approved for production In Production Testing
          6s 1
          Rakesh Roy (Inactive) made transition -
          In Production Testing Production Complete
          15s 1
          Hrishikesh Deshpande (Inactive) made transition -
          Production Complete Closed
          33d 42m 1

            People

            Assignee:
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive)
            Reporter:
            vijayendra Vijayendra Shinde (Inactive)
            Developer:
            Vijayendra Shinde (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Pre-Prod Due Date:
              Production Due Date: