[ 
https://issues.apache.org/jira/browse/OFBIZ-2074?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jacques Le Roux updated OFBIZ-2074:
-----------------------------------

    Attachment: requesthandler.patch

This patch version implement the (wronly names) grayList attribute in request 
map. The name will be changed to protect-view and the value set to false by 
default

As I said on dev ML  I'm really not satisified by my solution (I hard coded a 
method name). I guess I will try to rewrite it today.


> Grey list feature for confidential data access
> ----------------------------------------------
>
>                 Key: OFBIZ-2074
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-2074
>             Project: OFBiz
>          Issue Type: New Feature
>          Components: ALL COMPONENTS
>    Affects Versions: SVN trunk
>         Environment: NA
>            Reporter: Jacques Le Roux
>            Assignee: Jacques Le Roux
>            Priority: Minor
>         Attachments: requesthandler.patch, requesthandler.patch, 
> requesthandler.patch
>
>   Original Estimate: 20h
>  Remaining Estimate: 20h
>
> The goal is to avoid, as much as possible, confidential data leakage. 
> This feature will disallow access for a period of time to a view if this view 
> is accessed more than a number of time in a period of time. This will prevent 
> confidential data thievery done from a compromised login/pwd couple.

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.

Reply via email to