Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-5688

[Secure Test] Request Details of Get URL for viewing Benefit Descriptions are having parameters as plain text and using same URL plan descriptions can be accessed across company.

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: None
    • Labels:
      None
    • Environment:
      Production
    • Module:
      BenAdmin - Security
    • Reported by:
      Harbinger
    • Item State:
      Production QA

      Description

      [Secure Test] Request Details of Get URL for viewing Benefit Descriptions are having parameters as plain text and using same URL plan descriptions can be accessed across company.

      Start Tamper Data plugin for viewing Request Details.

      1. Login as Admin to Company 2.
      2. Login as Employee to Company 1
      3. Traverse Employee Self Serve mode to Enroll now plans like Medical,Dental,Vision etc.
      4. Click on Benefit Description
      5. Go to Tamper Data and check for the Request Details. Refer Screen Shots for details.
      6. Copy the URL and paste it in the Admin user's session of company 2
      7. Using same URL plan descriptions can be accessed across company.

      Refer screenshots for details

        Attachments

          Activity

          prasadp Prasad Pise (Inactive) created issue -
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Field Original Value New Value
          Status Open [ 1 ] In Development [ 10007 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Assignee Vijayendra Shinde [ ID10506 ] Prasad Pise [ prasadp ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Item State Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209)
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Module Parent values: BenAdmin(10100) Parent values: BenAdmin(10100)Level 1 values: Security(10112)
          ashwin.wankhede Ashwin Wankhede (Inactive) made changes -
          Item State Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209) Parent values: LB QA(10201)Level 1 values: LB Deployed(11600)
          rakeshr Rakesh Roy (Inactive) made changes -
          Issue Category EBS [ 10350 ] Harbinger [ 10700 ]
          prasadp Prasad Pise (Inactive) made changes -
          Attachment EmployeeSSM-1.jpg [ 31232 ]
          Attachment TamperedEmployeeSSM-2.jpg [ 31233 ]
          prasadp Prasad Pise (Inactive) made changes -
          Status In Development [ 10007 ] Local Testing [ 10200 ]
          prasadp Prasad Pise (Inactive) made changes -
          Status Local Testing [ 10200 ] Reopen in Local [ 10018 ]
          prasadp Prasad Pise (Inactive) made changes -
          Assignee Prasad Pise [ prasadp ] Vijayendra Shinde [ ID10506 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Status Reopen in Local [ 10018 ] In Development [ 10007 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Assignee Vijayendra Shinde [ ID10506 ] Prasad Pise [ prasadp ]
          prasadp Prasad Pise (Inactive) made changes -
          Status In Development [ 10007 ] Local Testing [ 10200 ]
          prasadp Prasad Pise (Inactive) made changes -
          Item State Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213)
          prasadp Prasad Pise (Inactive) made changes -
          Assignee Prasad Pise [ prasadp ] Vijayendra Shinde [ ID10506 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Assignee Vijayendra Shinde [ ID10506 ] Prasad Pise [ prasadp ]
          khandu.kshirsagar Khandu Kshirsagar (Inactive) made changes -
          Item State Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213) Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602)
          prasadp Prasad Pise (Inactive) made changes -
          Status Local Testing [ 10200 ] Stage Testing [ 10201 ]
          prasadp Prasad Pise (Inactive) made changes -
          Item State Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) Parent values: Stage QA(10202)Level 1 values: In Testing(10214)
          prasadp Prasad Pise (Inactive) made changes -
          Assignee Prasad Pise [ prasadp ] Rakesh Roy [ rakeshr ]
          rakeshr Rakesh Roy (Inactive) made changes -
          Assignee Rakesh Roy [ rakeshr ] Priya Dhamande [ priya.dhamande ]
          priya.dhamande Priya Dhamande (Inactive) made changes -
          Item State Parent values: Stage QA(10202)Level 1 values: In Testing(10214) Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217)
          priya.dhamande Priya Dhamande (Inactive) made changes -
          Assignee Priya Dhamande [ priya.dhamande ] Prasad Pise [ prasadp ]
          ashwin.wankhede Ashwin Wankhede (Inactive) made changes -
          Item State Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217) Parent values: Production QA(10203)Level 1 values: Production Deployed(10221)
          prasadp Prasad Pise (Inactive) made changes -
          Status Stage Testing [ 10201 ] Production Testing [ 10202 ]
          prasadp Prasad Pise (Inactive) made changes -
          Resolution Fixed [ 1 ]
          Status Production Testing [ 10202 ] Production Complete [ 10028 ]
          prasadp Prasad Pise (Inactive) made changes -
          Assignee Prasad Pise [ prasadp ] Rakesh Roy [ rakeshr ]
          priya.dhamande Priya Dhamande (Inactive) made changes -
          Item State Parent values: Production QA(10203)Level 1 values: Production Deployed(10221) Parent values: Production QA(10203)Level 1 values: In Testing(10218)
          priya.dhamande Priya Dhamande (Inactive) made changes -
          Item State Parent values: Production QA(10203)Level 1 values: In Testing(10218) Parent values: Production QA(10203)
          priya.dhamande Priya Dhamande (Inactive) made changes -
          Status Production Complete [ 10028 ] Closed [ 6 ]
          satyap Satya made changes -
          Environment_New Production [ 18442 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Link This issue relates to DEV-13718 [ DEV-13718 ]

            People

            Assignee:
            rakeshr Rakesh Roy (Inactive)
            Reporter:
            prasadp Prasad Pise (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: