[
https://issues.apache.org/jira/browse/SYNCOPE-719?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15075864#comment-15075864
]
ASF subversion and git services commented on SYNCOPE-719:
---------------------------------------------------------
Commit 8e8368e19772c5e39baa0a152e81a890f2cb6c3e in syncope's branch
refs/heads/master from [~andrea.patricelli]
[ https://git-wip-us.apache.org/repos/asf?p=syncope.git;h=8e8368e ]
[SYNCOPE-719] Added CSRF/XSRF protection by http cookie provided to angular
> UI enhancements
> ---------------
>
> Key: SYNCOPE-719
> URL: https://issues.apache.org/jira/browse/SYNCOPE-719
> Project: Syncope
> Issue Type: Sub-task
> Components: enduser
> Affects Versions: 2.0.0-M1
> Reporter: Andrea Patricelli
> Assignee: Andrea Patricelli
> Fix For: 2.0.0
>
>
> Enhancements to implement:
> - --Align login form to admin console's--
> - --Align derived and virtual attributes management to admin console's--
> - Add form frontend validation through AngularJS built-in form services.
> - Secure authentication process: at the moment username and password are
> passed "clearly" to wicket resource in the payload of the POST. to achieve
> this configure HTTPS connection.
> - Realms management (if needed): Add http resource to get available realms
> and possibiltity to select realm in user form.
> - Uploaded file preview (trivial, can even be ignored)
> - Add loading spinner to application:
> http://mvnrepository.com/artifact/org.webjars.bower/angular-spinner
> - --Add Resource management to create/edit user wizard (if needed).--
> - Add Group management to create/edit user wizard (if needed).
> - AngularJS unit testing: implement unit tests for angular frontend and
> possibly integrate them with maven build lifecycle.
> - Improve date management edit/create form: add timepicker when needed.
> - --Improve error and exception management: especially messages sent by
> resource to angular frontend.--
> - Add password stregth validator to user creation form.
> - --Add CAPTCHA field in self registration form.--
> - Add javadoc and if possible javascript doc
> - Add protection mechanisms against CSRF.
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)