Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Intelligence (Analytics)
Security of QueryString Parameters
midani
Hello I am using the free version of BIRT and need to know if there is the ability to secure a parameter being passed on the querystring so that a user may not edit it or see it on the querystring.
While testing I discovered that when one changes a querystring parameter from 25 or 253, they can see the other entities account information.
Thanks,
Find more posts tagged with
Comments
mwilliams
You're talking about someone changing the parameter in the URL, right? Not just changing it in the parameter page?
midani
Yes. I have investigated the other workspace that contains the window.open event that shows the url to the user, the code for that is here:
<![CDATA[
function Transfer(servlet){
var d1 = document.getElementById("sdate").value;
var d2 = document.getElementById("edate").value;
//window.open(servlet + '?sdate=' + d1 + '&edate=' + d2);
window.open(servlet + '?sdate=' + d1 + '&edate=' + d2+ '&caseid=' + document.form1.caseid.value+ '&homeid=' + document.form1.homeid.value+ '&parentid=' + document.form1.parentid.value+ '&userid=' + document.form1.userid.value+ '&mode=' + document.form1.mode.value);
}
function setDates( textBoxName ) {
frmSelectHome.sdate.disabled = false;
frmSelectHome.edate.disabled = false;
}
function infoMessage()
{
var s1 = document.getElementById("date").value;
if(s1 == null || s1 == "" || s1 == " ")
{
alert("Please enter a valid date!");
return false;
}
else
{
createReport('SelectReportingDoveRelease');
}
}
function createReport(servlet){
var s1 = document.getElementById("date").value;
//window.open(servlet + '?date=' + s1);
window.open(servlet + '?date=' + s1+ '&caseid=' + document.form1.caseid.value+ '&homeid=' + document.form1.homeid.value+ '&parentid=' + document.form1.parentid.value+ '&userid=' + document.form1.userid.value+ '&mode=' + document.form1.mode.value);
}
]]></script>
Unfortunately it is displaying the URL to the user on the BIRT reporting side of things. I have tried to set the location to no, but this is not working.
Do you have any ideas on how I can suppress it?
Thanks,
mwilliams
You could always encrypt the parameters before passing them in the URL, then decrypt them within your report, before using them.
Here's another option that someone has suggested using:
http://www.eclipse.org/forums/index.php/m/669357/
If those don't work, you're probably looking at modifying the viewer servlet, to have better security or moving to commercial BIRT, where this is already done.
http://www.birt-exchange.com/be/products/birt-design/birt-designer-pro/features/extensible-flexible-data-access-handling/