ivylabs / suitecrm-analytics

4 stars 4 forks source link

Obfuscate Report Chart URLS #217

Closed harrisward closed 3 years ago

harrisward commented 3 years ago

Is your feature request related to a problem? Please describe. We are using the Trusted User parameter in our CGG chart URLS in reports. Because of this its possible to access the charts directly if you know the username of a trusted user. To overcome this we could obfuscate the chart URL of the CHH wrapper script during the installation

Describe the solution you'd like During the setup of the BIServer we should generate a unique GUID and inject it into all of the PRPT files that contains charts. We also need to rename the CGG entry point script with this unique GUID