Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-1514

PASSWORD RETURNED IN SERVER RESPONSE

    Details

    • Type: Enhancement
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Affects Version/s: None
    • Fix Version/s: 1.0
    • Component/s: BenAdmin
    • Labels:
      None
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete
    • Sprint:
      WT Sprint 1

      Description

      Pretorian reported an issue that password is returning is server response is potential threat to system.

      The user’s password is returned in the response from the server when an administrator creates an account for a new employee
      By sending a user password as a response during account registration, WORKTERRA increases the possibility of the password being sniffed on the wire, or compromised via local workstation access.
      When registering a new employee, the employee's default password was displayed to the registrar.

      Ideally we should not display password to administrator.

      We need to find out all possible locations in System where we are sending password to client side.

      Possible solution for this is to remove add employee popup which displays credentials.
      Configuration flag should decide whether we need to display newly added employee password in alert or not.

        Attachments

        1. Add_Employee_Enhancement.doc
          81 kB
        2. Password Enhancement.xls
          18 kB
        3. Disply password flag settings.png
          Disply password flag settings.png
          176 kB
        4. Employee credencials.png
          Employee credencials.png
          173 kB
        5. Password credencial for SEO Module.png
          Password credencial for SEO Module.png
          178 kB
        6. Admin login.png
          Admin login.png
          179 kB

          Activity

          vijayendra Vijayendra Shinde (Inactive) created issue -
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Field Original Value New Value
          Status New Request [ 10029 ] Pending for Approval [ 10002 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Status Pending for Approval [ 10002 ] Approved for Development [ 10003 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Assignee Vijayendra Shinde [ ID10506 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Assignee Vijayendra Shinde [ ID10506 ] Swapnil Pandhare [ swapnil.pandhare ]
          samir Samir made changes -
          Status Approved for Development [ 10003 ] In Development [ 10007 ]
          Hide
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment -

          Due to other priority tasks, keeping this in Backlog.

          Show
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment - Due to other priority tasks, keeping this in Backlog.
          swapnil.pandhare Swapnil Pandhare (Inactive) made changes -
          Item State Parent values: Development(10200)Level 1 values: Development Backlog(10205)
          swapnil.pandhare Swapnil Pandhare (Inactive) made changes -
          Item State Parent values: Development(10200)Level 1 values: Development Backlog(10205) Parent values: Development(10200)Level 1 values: In Analysis(10204)
          Hide
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment -

          In analysis. We will share ETA by tomorrow.

          Show
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment - In analysis. We will share ETA by tomorrow.
          swapnil.pandhare Swapnil Pandhare (Inactive) made changes -
          Attachment Add_Employee_Enhancement.doc [ 14049 ]
          Hide
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment -

          FYI Satya , Samir

          Hi Vijayendra Shinde ,

          Can you please verify analysis document for this if it addresses the requirement ?

          Thanks,

          Show
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment - FYI Satya , Samir Hi Vijayendra Shinde , Can you please verify analysis document for this if it addresses the requirement ? Thanks,
          Hide
          vijayendra Vijayendra Shinde (Inactive) added a comment -

          Hi Swapnil,

          Document looks good to me. You can proceed with development for this. Please make sure we are adding flag in relevant section on Security page.

          Thanks.

          Show
          vijayendra Vijayendra Shinde (Inactive) added a comment - Hi Swapnil, Document looks good to me. You can proceed with development for this. Please make sure we are adding flag in relevant section on Security page. Thanks.
          Hide
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment -

          Due to short of bandwidth , we are keeping this enhancement on Hold.

          Show
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment - Due to short of bandwidth , we are keeping this enhancement on Hold.
          swapnil.pandhare Swapnil Pandhare (Inactive) made changes -
          Item State Parent values: Development(10200)Level 1 values: In Analysis(10204) Parent values: Development(10200)Level 1 values: On Hold(10207)
          satyap Satya made changes -
          Dev Estimates 24
          satyap Satya made changes -
          Component/s BenAdmin [ 10000 ]
          Component/s BenAdmin [ 10100 ]
          Issue Type Enhancement [ 4 ] Change Request [ 10002 ]
          Key ST-89 WT-1514
          Project Project Simple [ 10400 ] WORKTERRA [ 10000 ]
          deepalit Deepali Tidke (Inactive) made changes -
          QA Estimates 12
          admin01 admin made changes -
          Fix Version/s 1.0 [ 10000 ]
          Hide
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment -

          Hi Chaitali,

          We will start with this enhancement today.

          Show
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment - Hi Chaitali, We will start with this enhancement today.
          swapnil.pandhare Swapnil Pandhare (Inactive) made changes -
          Assignee Swapnil Pandhare [ swapnil.pandhare ] Chaitali Acharya [ chaitali.acharya ]
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Issue Type Change Request [ 10002 ] Enhancement [ 4 ]
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Issue Type Enhancement [ 4 ] Change Request [ 10002 ]
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Status In Development [ 10007 ] Local Testing [ 10200 ]
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Status Local Testing [ 10200 ] Reopen in Local [ 10018 ]
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Status Reopen in Local [ 10018 ] In Development [ 10007 ]
          Hide
          chaitali.acharya Chaitali Acharya (Inactive) added a comment -

          Started with the enhancement today.

          Show
          chaitali.acharya Chaitali Acharya (Inactive) added a comment - Started with the enhancement today.
          rakeshr Rakesh Roy (Inactive) made changes -
          Account Executive David Rhodes [Administrator] [ admin ]
          Hide
          chaitali.acharya Chaitali Acharya (Inactive) added a comment -

          Code related changes are committed on LB
          DB Script changes are yet to be deployed on LB .It will be deployed on LB tomorrow.
          So will change the status accordingly tomorrow.

          Show
          chaitali.acharya Chaitali Acharya (Inactive) added a comment - Code related changes are committed on LB DB Script changes are yet to be deployed on LB .It will be deployed on LB tomorrow. So will change the status accordingly tomorrow.
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Issue Type Change Request [ 10002 ] Enhancement [ 4 ]
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Issue Type Enhancement [ 4 ] Change Request [ 10002 ]
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Issue Type Change Request [ 10002 ] Enhancement [ 4 ]
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Item State Parent values: Development(10200)Level 1 values: On Hold(10207) Parent values: LB QA(10201)
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Status In Development [ 10007 ] Local Testing [ 10200 ]
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Assignee Chaitali Acharya [ chaitali.acharya ] Deepali Tidke [ deepalit ]
          Hide
          chaitali.acharya Chaitali Acharya (Inactive) added a comment -

          Deepali Tidke
          This is deployed on LB.

          Show
          chaitali.acharya Chaitali Acharya (Inactive) added a comment - Deepali Tidke This is deployed on LB.
          deepalit Deepali Tidke (Inactive) made changes -
          Assignee Deepali Tidke [ deepalit ] Venkatesh Pujari [ venkatesh.pujari ]
          venkatesh.pujari Venkatesh Pujari (Inactive) made changes -
          Attachment Password Enhancement.xls [ 15315 ]
          Hide
          venkatesh.pujari Venkatesh Pujari (Inactive) added a comment -

          Please note that if the employee is not given any email address while adding him into the system the credentials will not be sent to anyone(employee nor admin).

          Show
          venkatesh.pujari Venkatesh Pujari (Inactive) added a comment - Please note that if the employee is not given any email address while adding him into the system the credentials will not be sent to anyone(employee nor admin).
          satyap Satya made changes -
          Sprint WT Sprint 1 [ 6 ]
          satyap Satya made changes -
          Rank Ranked higher
          venkatesh.pujari Venkatesh Pujari (Inactive) made changes -
          Item State Parent values: LB QA(10201) Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213)
          satyap Satya made changes -
          Rank Ranked higher
          swapnil.pandhare Swapnil Pandhare (Inactive) made changes -
          Status Local Testing [ 10200 ] Reopen in Local [ 10018 ]
          swapnil.pandhare Swapnil Pandhare (Inactive) made changes -
          Status Reopen in Local [ 10018 ] In Development [ 10007 ]
          swapnil.pandhare Swapnil Pandhare (Inactive) made changes -
          Status In Development [ 10007 ] Local Testing [ 10200 ]
          swapnil.pandhare Swapnil Pandhare (Inactive) made changes -
          Status Local Testing [ 10200 ] Pending for Stage Approval [ 10300 ]
          satyap Satya made changes -
          Status Pending for Stage Approval [ 10300 ] Approved for Stage [ 10030 ]
          Hide
          chaitali.acharya Chaitali Acharya (Inactive) added a comment -

          Checked into Stage

          Show
          chaitali.acharya Chaitali Acharya (Inactive) added a comment - Checked into Stage
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Status Approved for Stage [ 10030 ] Stage Testing [ 10201 ]
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Item State Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213) Parent values: Stage QA(10202)
          Hide
          venkatesh.pujari Venkatesh Pujari (Inactive) added a comment -

          Please assign this ticket to someone

          Show
          venkatesh.pujari Venkatesh Pujari (Inactive) added a comment - Please assign this ticket to someone
          venkatesh.pujari Venkatesh Pujari (Inactive) made changes -
          Assignee Venkatesh Pujari [ venkatesh.pujari ] Deepali Tidke [ deepalit ]
          Hide
          deepalit Deepali Tidke (Inactive) added a comment -

          kindly check this and discuss once with Venkatesh before starting it.

          Show
          deepalit Deepali Tidke (Inactive) added a comment - kindly check this and discuss once with Venkatesh before starting it.
          deepalit Deepali Tidke (Inactive) made changes -
          Assignee Deepali Tidke [ deepalit ] Dhanashree Sherkar [ dhanashree.sherkar ]
          Hide
          dhanashree.sherkar Dhanashree Sherkar (Inactive) added a comment -

          Verified on stage.
          Company name:- 1.OCSD for hspl
          2.City of Durham For HSPL
          Log in:-1.Partner
          2.Admin
          On security page system displayed check box for 'To Display Password on Add Employee.'
          Admin/partner can check or uncheck check box for password.
          refer attached screenshot.

          On Add employee page system not displayed employee credential for uncheck.
          Employee credential pop up displayed when check box is selected.
          Refer attached screenshot.

          above scenarios tested for benadmin & Recruit module.
          For SEO testing is in progress.

          Show
          dhanashree.sherkar Dhanashree Sherkar (Inactive) added a comment - Verified on stage. Company name:- 1.OCSD for hspl 2.City of Durham For HSPL Log in:-1.Partner 2.Admin On security page system displayed check box for 'To Display Password on Add Employee.' Admin/partner can check or uncheck check box for password. refer attached screenshot. On Add employee page system not displayed employee credential for uncheck. Employee credential pop up displayed when check box is selected. Refer attached screenshot. above scenarios tested for benadmin & Recruit module. For SEO testing is in progress.
          dhanashree.sherkar Dhanashree Sherkar (Inactive) made changes -
          Attachment Disply password flag settings.png [ 16421 ]
          dhanashree.sherkar Dhanashree Sherkar (Inactive) made changes -
          Attachment Employee credencials.png [ 16422 ]
          dhanashree.sherkar Dhanashree Sherkar (Inactive) made changes -
          dhanashree.sherkar Dhanashree Sherkar (Inactive) made changes -
          Attachment Admin login.png [ 16424 ]
          Hide
          deepalit Deepali Tidke (Inactive) added a comment -

          Foe SEO also it is checked. ready for production.

          Show
          deepalit Deepali Tidke (Inactive) added a comment - Foe SEO also it is checked. ready for production.
          deepalit Deepali Tidke (Inactive) made changes -
          Item State Parent values: Stage QA(10202) Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217)
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Item State Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217) Parent values: Production QA(10203)
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Status Stage Testing [ 10201 ] Pending for Production Approval [ 10301 ]
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Status Pending for Production Approval [ 10301 ] Approved for production [ 10034 ]
          chaitali.acharya Chaitali Acharya (Inactive) made changes -
          Status Approved for production [ 10034 ] Production Testing [ 10202 ]
          Hide
          deepalit Deepali Tidke (Inactive) added a comment -

          kindly check this on production

          Show
          deepalit Deepali Tidke (Inactive) added a comment - kindly check this on production
          deepalit Deepali Tidke (Inactive) made changes -
          Assignee Dhanashree Sherkar [ dhanashree.sherkar ] Kunal Kedari [ kunal.kedari ]
          Hide
          kunal.kedari Kunal Kedari (Inactive) added a comment -

          We have verified the enhancement on Production for BenAdmin & Recruit module, working as expected.

          Show
          kunal.kedari Kunal Kedari (Inactive) added a comment - We have verified the enhancement on Production for BenAdmin & Recruit module, working as expected.
          kunal.kedari Kunal Kedari (Inactive) made changes -
          Resolution Done [ 10000 ]
          Status Production Testing [ 10202 ] Production Complete [ 10028 ]
          kunal.kedari Kunal Kedari (Inactive) made changes -
          Item State Parent values: Production QA(10203) Parent values: Production Complete(10222)
          Hide
          kunal.kedari Kunal Kedari (Inactive) added a comment - - edited

          This is deployed and verified on production.

          Show
          kunal.kedari Kunal Kedari (Inactive) added a comment - - edited This is deployed and verified on production.
          kunal.kedari Kunal Kedari (Inactive) made changes -
          Assignee Kunal Kedari [ kunal.kedari ] Jennifer Leugers [ jennifer.leugers ]
          satyap Satya made changes -
          Resolution Done [ 10000 ] Fixed [ 1 ]
          Status Production Complete [ 10028 ] Closed [ 6 ]
          Hide
          satyap Satya added a comment -

          This fix has been done as part of Security testing points reported from Praetorian.

          Show
          satyap Satya added a comment - This fix has been done as part of Security testing points reported from Praetorian.
          Transition Time In Source Status Execution Times
          Vijayendra Shinde (Inactive) made transition -
          New Request Pending for Approval
          23s 1
          Vijayendra Shinde (Inactive) made transition -
          Pending for Approval Approved for Development
          4s 1
          Samir made transition -
          Approved for Development In Development
          21h 7m 1
          Swapnil Pandhare (Inactive) made transition -
          In LB Testing Reopen in Local
          8d 5h 40m 2
          Swapnil Pandhare (Inactive) made transition -
          Reopen in Local In Development
          1h 7m 2
          Swapnil Pandhare (Inactive) made transition -
          In Development In LB Testing
          20d 22h 22m 3
          Swapnil Pandhare (Inactive) made transition -
          In LB Testing Pending for Stage Approval
          3s 1
          Satya made transition -
          Pending for Stage Approval Approved for Stage
          1m 16s 1
          Chaitali Acharya (Inactive) made transition -
          Approved for Stage Stage Testing
          3d 19h 47m 1
          Chaitali Acharya (Inactive) made transition -
          Stage Testing Pending for Production Approval
          14d 23h 46m 1
          Chaitali Acharya (Inactive) made transition -
          Pending for Production Approval Approved for production
          2s 1
          Chaitali Acharya (Inactive) made transition -
          Approved for production In Production Testing
          3s 1
          Kunal Kedari (Inactive) made transition -
          In Production Testing Production Complete
          1d 3h 4m 1
          Satya made transition -
          Production Complete Closed
          54m 18s 1

            People

            Assignee:
            jennifer.leugers Jennifer Leugers
            Reporter:
            vijayendra Vijayendra Shinde (Inactive)
            Account Executive:
            David Rhodes (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            8 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: