AnsweredAssumed Answered

Encode information in URL

Question asked by ankurkhandelwal on Apr 16, 2013
Hi All,

I am using Alfresco 3.4 with apache tomcat 6.0.26.

In tasklist-min.js file I have encoded a component of Alfresco.constants.username but security Team of my client has reported that the URI is showing user name and needs to be encoded.

my url is

var url = Alfresco.constants.PROXY_URI + "api/task-instances?authority=" + encodeURIComponent(Alfresco.constants.USERNAME) +
               "&properties=" + ["bpm_priority", "bpm_status", "bpm_dueDate", "bpm_description"].join(",") +
               "&exclude=" + this.options.hiddenTaskTypes.join(",");



I have encoded the Alfresco.constants.USERNAME but it is not getting encoded and on making an alert it shows like this

<b>http://localhost:8080/share/proxy/alfresco/api/task-instances?authority=admin&properties=bpm_priority,bpm_status,bpm_dueDate,bpm_description&exclude=wcmwf:*</b>

Can anybody guide as how can I encode the username so that it may not reveal it

Outcomes