Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-1514

PASSWORD RETURNED IN SERVER RESPONSE

    Details

    • Type: Enhancement
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Affects Version/s: None
    • Fix Version/s: 1.0
    • Component/s: BenAdmin
    • Labels:
      None
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete
    • Sprint:
      WT Sprint 1

      Description

      Pretorian reported an issue that password is returning is server response is potential threat to system.

      The user’s password is returned in the response from the server when an administrator creates an account for a new employee
      By sending a user password as a response during account registration, WORKTERRA increases the possibility of the password being sniffed on the wire, or compromised via local workstation access.
      When registering a new employee, the employee's default password was displayed to the registrar.

      Ideally we should not display password to administrator.

      We need to find out all possible locations in System where we are sending password to client side.

      Possible solution for this is to remove add employee popup which displays credentials.
      Configuration flag should decide whether we need to display newly added employee password in alert or not.

        Attachments

        1. Add_Employee_Enhancement.doc
          81 kB
        2. Admin login.png
          Admin login.png
          179 kB
        3. Disply password flag settings.png
          Disply password flag settings.png
          176 kB
        4. Employee credencials.png
          Employee credencials.png
          173 kB
        5. Password credencial for SEO Module.png
          Password credencial for SEO Module.png
          178 kB
        6. Password Enhancement.xls
          18 kB

          Activity

          Hide
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment -

          Due to other priority tasks, keeping this in Backlog.

          Show
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment - Due to other priority tasks, keeping this in Backlog.
          Hide
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment -

          In analysis. We will share ETA by tomorrow.

          Show
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment - In analysis. We will share ETA by tomorrow.
          Hide
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment -

          FYI Satya , Samir

          Hi Vijayendra Shinde ,

          Can you please verify analysis document for this if it addresses the requirement ?

          Thanks,

          Show
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment - FYI Satya , Samir Hi Vijayendra Shinde , Can you please verify analysis document for this if it addresses the requirement ? Thanks,
          Hide
          vijayendra Vijayendra Shinde (Inactive) added a comment -

          Hi Swapnil,

          Document looks good to me. You can proceed with development for this. Please make sure we are adding flag in relevant section on Security page.

          Thanks.

          Show
          vijayendra Vijayendra Shinde (Inactive) added a comment - Hi Swapnil, Document looks good to me. You can proceed with development for this. Please make sure we are adding flag in relevant section on Security page. Thanks.
          Hide
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment -

          Due to short of bandwidth , we are keeping this enhancement on Hold.

          Show
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment - Due to short of bandwidth , we are keeping this enhancement on Hold.
          Hide
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment -

          Hi Chaitali,

          We will start with this enhancement today.

          Show
          swapnil.pandhare Swapnil Pandhare (Inactive) added a comment - Hi Chaitali, We will start with this enhancement today.
          Hide
          chaitali.acharya Chaitali Acharya (Inactive) added a comment -

          Started with the enhancement today.

          Show
          chaitali.acharya Chaitali Acharya (Inactive) added a comment - Started with the enhancement today.
          Hide
          chaitali.acharya Chaitali Acharya (Inactive) added a comment -

          Code related changes are committed on LB
          DB Script changes are yet to be deployed on LB .It will be deployed on LB tomorrow.
          So will change the status accordingly tomorrow.

          Show
          chaitali.acharya Chaitali Acharya (Inactive) added a comment - Code related changes are committed on LB DB Script changes are yet to be deployed on LB .It will be deployed on LB tomorrow. So will change the status accordingly tomorrow.
          Hide
          chaitali.acharya Chaitali Acharya (Inactive) added a comment -

          Deepali Tidke
          This is deployed on LB.

          Show
          chaitali.acharya Chaitali Acharya (Inactive) added a comment - Deepali Tidke This is deployed on LB.
          Hide
          venkatesh.pujari Venkatesh Pujari (Inactive) added a comment -

          Please note that if the employee is not given any email address while adding him into the system the credentials will not be sent to anyone(employee nor admin).

          Show
          venkatesh.pujari Venkatesh Pujari (Inactive) added a comment - Please note that if the employee is not given any email address while adding him into the system the credentials will not be sent to anyone(employee nor admin).
          Hide
          chaitali.acharya Chaitali Acharya (Inactive) added a comment -

          Checked into Stage

          Show
          chaitali.acharya Chaitali Acharya (Inactive) added a comment - Checked into Stage
          Hide
          venkatesh.pujari Venkatesh Pujari (Inactive) added a comment -

          Please assign this ticket to someone

          Show
          venkatesh.pujari Venkatesh Pujari (Inactive) added a comment - Please assign this ticket to someone
          Hide
          deepalit Deepali Tidke (Inactive) added a comment -

          kindly check this and discuss once with Venkatesh before starting it.

          Show
          deepalit Deepali Tidke (Inactive) added a comment - kindly check this and discuss once with Venkatesh before starting it.
          Hide
          dhanashree.sherkar Dhanashree Sherkar (Inactive) added a comment -

          Verified on stage.
          Company name:- 1.OCSD for hspl
          2.City of Durham For HSPL
          Log in:-1.Partner
          2.Admin
          On security page system displayed check box for 'To Display Password on Add Employee.'
          Admin/partner can check or uncheck check box for password.
          refer attached screenshot.

          On Add employee page system not displayed employee credential for uncheck.
          Employee credential pop up displayed when check box is selected.
          Refer attached screenshot.

          above scenarios tested for benadmin & Recruit module.
          For SEO testing is in progress.

          Show
          dhanashree.sherkar Dhanashree Sherkar (Inactive) added a comment - Verified on stage. Company name:- 1.OCSD for hspl 2.City of Durham For HSPL Log in:-1.Partner 2.Admin On security page system displayed check box for 'To Display Password on Add Employee.' Admin/partner can check or uncheck check box for password. refer attached screenshot. On Add employee page system not displayed employee credential for uncheck. Employee credential pop up displayed when check box is selected. Refer attached screenshot. above scenarios tested for benadmin & Recruit module. For SEO testing is in progress.
          Hide
          deepalit Deepali Tidke (Inactive) added a comment -

          Foe SEO also it is checked. ready for production.

          Show
          deepalit Deepali Tidke (Inactive) added a comment - Foe SEO also it is checked. ready for production.
          Hide
          deepalit Deepali Tidke (Inactive) added a comment -

          kindly check this on production

          Show
          deepalit Deepali Tidke (Inactive) added a comment - kindly check this on production
          Hide
          kunal.kedari Kunal Kedari (Inactive) added a comment -

          We have verified the enhancement on Production for BenAdmin & Recruit module, working as expected.

          Show
          kunal.kedari Kunal Kedari (Inactive) added a comment - We have verified the enhancement on Production for BenAdmin & Recruit module, working as expected.
          Hide
          kunal.kedari Kunal Kedari (Inactive) added a comment - - edited

          This is deployed and verified on production.

          Show
          kunal.kedari Kunal Kedari (Inactive) added a comment - - edited This is deployed and verified on production.
          Hide
          satyap Satya added a comment -

          This fix has been done as part of Security testing points reported from Praetorian.

          Show
          satyap Satya added a comment - This fix has been done as part of Security testing points reported from Praetorian.

            People

            Assignee:
            jennifer.leugers Jennifer Leugers
            Reporter:
            vijayendra Vijayendra Shinde (Inactive)
            Account Executive:
            David Rhodes (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            8 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: