Uploaded image for project: 'camunda BPM'
  1. camunda BPM
  2. CAM-8443

I can read documentation about security topics to consider when running Camunda

      Topics that should be covered in [1]:

      • How to configure session timeout
      • How to configure https only
      • How to configure cookies domain
      • BPMN (containing scripts) / Forms should be deployed by a "trustful" employee
      • Forms: input validation (cross-site script attack)
      • SQL Injection when using native queries -> (User builds his own app by using native queries)
      • How to configure max post size in server (REST API)
      • How to delete demo user

      AT:

      • The documentation should not contain a step by step description how to configure something.
      • It should point out that these topics should be considered during the setup of Camunda.
      • There should be a link to show for example how to configure session timeouts on tomcat.

      [1]: https://docs.camunda.org/manual/7.7/user-guide/security/

        This is the controller panel for Smart Panels app

            [CAM-8443] I can read documentation about security topics to consider when running Camunda

            Roman Smirnov created issue -
            Roman Smirnov made changes -
            Summary Original: I can read documentation about New: I can read documentation about security topics to consider when running Camunda
            Roman Smirnov made changes -
            Labels New: documentation
            Yana Vasileva made changes -
            Description Original: Topics that should be covered in [1]:
            - How to configure session timeout
            - How to configure https only
            - How to configure cookies domain
            - BPMN (containing scripts) / Forms should be deployed by a "trustful" employee
            - Forms: input validation (cross-site script attack)
            - SQL Injection when using native queries -> (User builds his own app by using native queries)
            - How to configure max post size in server (REST API)
            - How to delete demo user

            AT:
            * The documentation should not contain a step by step description how to configure something.
            * It should point out that these topics should be considered during the setup of Camunda.
            * There should be example a link to show for example how to configure session timeouts on tomcat.

            [1]: https://docs.camunda.org/manual/7.7/user-guide/security/
            New: Topics that should be covered in [1]:
            - How to configure session timeout
            - How to configure https only
            - How to configure cookies domain
            - BPMN (containing scripts) / Forms should be deployed by a "trustful" employee
            - Forms: input validation (cross-site script attack)
            - SQL Injection when using native queries -> (User builds his own app by using native queries)
            - How to configure max post size in server (REST API)
            - How to delete demo user

            AT:
            * The documentation should not contain a step by step description how to configure something.
            * It should point out that these topics should be considered during the setup of Camunda.
            * There should be a link to show for example how to configure session timeouts on tomcat.

            [1]: https://docs.camunda.org/manual/7.7/user-guide/security/
            Yana Vasileva made changes -
            Status Original: Open [ 1 ] New: In Progress [ 3 ]

            • please return it back after the review, so I can show the changes also to Robert

            Yana Vasileva added a comment - please return it back after the review, so I can show the changes also to Robert
            Yana Vasileva made changes -
            Assignee Original: Yana Vasileva [ yana.vasileva ] New: Svetlana Dorokhova [ svetlana.dorokhova ]
            Resolution New: Fixed [ 1 ]
            Status Original: In Progress [ 3 ] New: Resolved [ 5 ]
            Remaining Estimate New: 0 minutes [ 0 ]
            Original Estimate New: 0 minutes [ 0 ]
            Svetlana Dorokhova made changes -
            Assignee Original: Svetlana Dorokhova [ svetlana.dorokhova ] New: Yana Vasileva [ yana.vasileva ]
            Matthijs made changes -
            Assignee Original: Yana Vasileva [ yana.vasileva ] New: Matthijs [ matthijs.burke ]
            Yana Vasileva made changes -
            Assignee Original: Matthijs [ matthijs.burke ] New: Yana Vasileva [ yana.vasileva ]

              roman.smirnov Roman Smirnov
              roman.smirnov Roman Smirnov
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: