Uploaded image for project: 'Project Simple'
  1. Project Simple
  2. ST-251

Report query string parameterization

    Details

    • Type: Enhancement
    • Status: Closed
    • Priority: Critical
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
      None
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Issue Importance:
      Must Have

      Description

      All parameters are visible in browser when user view report.

      Resolution:
      We should encrypt report query string parameters so that user should not be able to manipulate reports.

        Attachments

          Activity

          Hide
          vijayendra Vijayendra Shinde (Inactive) added a comment -

          We are working on encrypting parameters of Reports.

          Show
          vijayendra Vijayendra Shinde (Inactive) added a comment - We are working on encrypting parameters of Reports.
          Hide
          vijayendra Vijayendra Shinde (Inactive) added a comment -

          Affected Files:

          SharedFunctionWebTier/SharedFunctionWebTier/Views/Shared/_WORKTERRALayout.cshtml
          SharedFunctionWebTier/SharedFunctionWebTier/Views/Shared/_WORKTERRALayout.generated.cs
          Web Projects/BenAdmin/Scripts/WORKTERRAShared.js
          Web Projects/WORKTERRA/ReportViewer/ViewReport.aspx.cs

          Show
          vijayendra Vijayendra Shinde (Inactive) added a comment - Affected Files: SharedFunctionWebTier/SharedFunctionWebTier/Views/Shared/_WORKTERRALayout.cshtml SharedFunctionWebTier/SharedFunctionWebTier/Views/Shared/_WORKTERRALayout.generated.cs Web Projects/BenAdmin/Scripts/WORKTERRAShared.js Web Projects/WORKTERRA/ReportViewer/ViewReport.aspx.cs
          Hide
          deepalit Deepali Tidke (Inactive) added a comment -

          Checked the company level reports on LB from partner, CA and EE login >> on report run >> parameters are encrypted now.

          Sachin Hingole checked the ACA reports on lb and they are also encrypted.

          For Global level reports , encryption is not coming as it not implemented at global level

          Show
          deepalit Deepali Tidke (Inactive) added a comment - Checked the company level reports on LB from partner, CA and EE login >> on report run >> parameters are encrypted now. Sachin Hingole checked the ACA reports on lb and they are also encrypted. For Global level reports , encryption is not coming as it not implemented at global level
          Hide
          deepalit Deepali Tidke (Inactive) added a comment -

          Checked the company level reports on stage from partner, CA and EE login >> on report run >> parameters are encrypted now.

          For Global level reports , encryption is not coming as it not implemented at global level

          Sachin Hingole please check ACA level reports on stage.

          Show
          deepalit Deepali Tidke (Inactive) added a comment - Checked the company level reports on stage from partner, CA and EE login >> on report run >> parameters are encrypted now. For Global level reports , encryption is not coming as it not implemented at global level Sachin Hingole please check ACA level reports on stage.
          Hide
          sachin.hingole Sachin Hingole (Inactive) added a comment -

          Verified ACA reports on stage and they are also encrypted.
          Also reports are opening without error.

          Show
          sachin.hingole Sachin Hingole (Inactive) added a comment - Verified ACA reports on stage and they are also encrypted. Also reports are opening without error.

            People

            Assignee:
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive)
            Reporter:
            vijayendra Vijayendra Shinde (Inactive)
            Developer:
            Vijayendra Shinde (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Pre-Prod Due Date:
              Production Due Date: