GSA / gsa-doc-digital-signature

This tool is deprecated. Please follow these new procedures - https://playbooks.idmanagement.gov/signfedregister/
Other
20 stars 7 forks source link

Unpack feature no longer creates *.up7 extension #18

Open powell-ofr opened 7 years ago

powell-ofr commented 7 years ago

The Unpack feature of the GSA signing tool no longer renders a filename with the .up7 extension. It renders a Word document that simply overwrites the original document, negating the whole point of unpacking. Is it possible to get the .up7 extension reinstituted?

Lee Powell OFR

powell-ofr commented 7 years ago

Any action or response on this? I've been told time and time again to leave a message here but I haven't heard back.

Lee Powell OFR

djpackham commented 7 years ago

@powell-ofr Thanks for submitting the issue about needing to change the filename extension when a signed file is "unpacked".

We don't have any releases scheduled for updating the tool in the near future. Part of the reason we moved the issuing tracking and source code to GitHub is if an immediate update is needed, the community has the ability to update and share the source code for the fix they need.

Are you hearing from a lot of agencies of this being a hassle?

powell-ofr commented 7 years ago

Of course I’m not “hearing from a lot of agencies,” but the few who do ask me about it now have to be careful not to overwrite an original document with potentially the wrong document.

I guess I’ll tell them to work around it.

Most of the tool users I talk to have no idea how to code, so writing their own code Is not an option.

powell-ofr commented 7 years ago

The emphasis of concern on this thread is the danger of overwriting a file when a signed (.p7m) file is unpacked. Since there is no longer a .up7 extension in the unpacked file's filename, it would be easy to inadvertently replace the proper *.docx file because the "File Destination" field is fixed and uneditable.
Therefore, I suggest making the "File Destination" field user-editable. It seems like a fairly straightforward fix and if I knew any coding I'd do it myself.

djpackham commented 7 years ago

@powell-ofr

Roger that. Thanks for the detailed info. It is definitely on our radar to fix.