<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Securing Activiti Modeler in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129053#M90678</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;balsarori, thanks. Imho, this is a very important feature and should be merged immediately.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Mar 2015 07:44:42 GMT</pubDate>
    <dc:creator>b_schnarr</dc:creator>
    <dc:date>2015-03-04T07:44:42Z</dc:date>
    <item>
      <title>Securing Activiti Modeler</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129045#M90670</link>
      <description>Currently, Activiti Modeler can be accessed (and models can be modified) without authentication by directly accessing the Modeler, for example:http://localhost:8080/activiti-explorer2/service/editor?id=50Of course, there are different options for administrators to handle this but I think that it sho</description>
      <pubDate>Mon, 11 Mar 2013 00:37:37 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129045#M90670</guid>
      <dc:creator>balsarori</dc:creator>
      <dc:date>2013-03-11T00:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Activiti Modeler</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129046#M90671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Yes, I think that is indeed needed (and we discussed it too already, agreeing we need to add it asap).&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2013 10:51:10 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129046#M90671</guid>
      <dc:creator>jbarrez</dc:creator>
      <dc:date>2013-03-11T10:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Activiti Modeler</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129047#M90672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I'm not sure whats the best way to do this. Anyway, here is what I think can be one option&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://github.com/balsarori/Activiti/commit/4a42468048ac5cd2ec139f519348b62bbab804e2" rel="nofollow noopener noreferrer"&gt;https://github.com/balsarori/Activiti/commit/4a42468048ac5cd2ec139f519348b62bbab804e2&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In this code any call to '/service' will not be allowed unless user was already authenticated (either by Vaadin login form or by Servlet Container). When a user logins to Explorer an attribute is saved in the session (the user id, could be anything else). ExplorerFilter checks for this attribute and will not allow access to '/service' unless this attribute was set or user was authenticated by Servlet Container.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Mar 2013 01:34:39 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129047#M90672</guid>
      <dc:creator>balsarori</dc:creator>
      <dc:date>2013-03-12T01:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Activiti Modeler</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129048#M90673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Yes, that makes sense. We'll discuss it shortly, and I have put your link on my notes. Thanks!&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 08:59:38 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129048#M90673</guid>
      <dc:creator>jbarrez</dc:creator>
      <dc:date>2013-03-13T08:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Activiti Modeler</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129049#M90674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Can you provide any update? This appears to still be an issue, as of 5.16. In the meantime, is there any way to completely disable modeler (without deploying an SSL decrypting WAF, that is). Unfortunately, I can't deploy Activiti into production with such a severe vulnerability. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;EDIT: I notice that JIRA ticket ACT-1970 tracks this, filed at the end of March 2014, but is marked as minor priority. This vulnerability, unless mitigated, would prevent Activiti Explorer's use in any enterprise, so might justify a higher priority. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2014 19:08:15 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129049#M90674</guid>
      <dc:creator>mathewjohnston</dc:creator>
      <dc:date>2014-09-17T19:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Activiti Modeler</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129050#M90675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Any updates on this issue?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The above fix worked.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Feb 2015 15:57:08 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129050#M90675</guid>
      <dc:creator>fionn</dc:creator>
      <dc:date>2015-02-02T15:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Activiti Modeler</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129051#M90676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Ideally that fix is added to the code. Not sure if it covers all use cases.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;A pull request would most certainly be appreciated, if you say you've successfully verified it!&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Feb 2015 16:18:02 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129051#M90676</guid>
      <dc:creator>jbarrez</dc:creator>
      <dc:date>2015-02-09T16:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Activiti Modeler</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129052#M90677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I've created a pull request that secures access to /service, process definitions and models should now be accessible to authenticated users only.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://github.com/Activiti/Activiti/pull/533" rel="nofollow noopener noreferrer"&gt;https://github.com/Activiti/Activiti/pull/533&lt;/A&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Mar 2015 01:17:06 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129052#M90677</guid>
      <dc:creator>balsarori</dc:creator>
      <dc:date>2015-03-04T01:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Activiti Modeler</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129053#M90678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;balsarori, thanks. Imho, this is a very important feature and should be merged immediately.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Mar 2015 07:44:42 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/securing-activiti-modeler/m-p/129053#M90678</guid>
      <dc:creator>b_schnarr</dc:creator>
      <dc:date>2015-03-04T07:44:42Z</dc:date>
    </item>
  </channel>
</rss>

