Project

General

Profile

Actions

Task #4242

closed

Hawat: Merge reports/view and reports/unauth views

Added by Jan Mach over 6 years ago. Updated about 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Development - GUI
Target version:
Start date:
08/02/2018
Due date:
% Done:

100%

Estimated time:
To be discussed:

Description

The idea behind reports/unauth view was to enable access to report data even to unauthenticated users, so that they can be easily shared. The hash for unauthenticated access serves as a password, but it is contained within the email in clear text form. Another identifier is report label, which also contains random part. Since both of these identifiers are sent in clear text form and contain random parts, it might be better so simplify things and use just label for accessing the reports and hide anything sensitive or inaccessible until login.


Related issues

Related to Mentat - Bug #4240: When accessing report in unauthenticated mode it is not possible to load report JSON data file in Data tabClosedJan Mach08/02/2018

Actions
Actions #1

Updated by Jan Mach over 6 years ago

  • Related to Bug #4240: When accessing report in unauthenticated mode it is not possible to load report JSON data file in Data tab added
Actions #2

Updated by Jan Mach over 6 years ago

  • Target version changed from Backlog to 2.1
Actions #3

Updated by Jan Mach about 6 years ago

  • Target version changed from 2.1 to 2.2
Actions #4

Updated by Jan Mach about 6 years ago

  • Status changed from New to In Progress
Actions #5

Updated by Jan Mach about 6 years ago

  • Status changed from In Progress to Feedback
  • % Done changed from 0 to 100

I have not merged the views, because it turned out to be wrong idea. I have however removed the handle attribute from the report model, because the report label contains random component and can be used as secret access token instead. This patch sadly introduces BC break, because old access tokens stored within the mailed reports will no longer work. I think, that this should not cause much problems, because users prefer to use the authenticated approach.

I have deployed the code to mentat-alt for testing over the weekend.

Actions #6

Updated by Jan Mach about 6 years ago

  • Status changed from Feedback to Closed

Current solution accepted.

Actions

Also available in: Atom PDF