BPM, Workflow, and Case

BPM, Workflow, and Case

Come for answers. Stay for best practices. All we’re missing is you.

 View Only
  • 1.  Case Property Write issue

    Posted Wed September 11, 2024 07:36 AM

    Hi Team,

    We have a workflow having worker, manager and approver role where Approver should not able to update the property value instead Approve or Reject action on the case and that we have achieved by restricting from the front end. 

    Third party security testing team found security vulnerability where from backend Approver can able to modify/update the properties value using some Burp penetration tool.

    Can you please guide how to restrict Approver to make modification i.e. that check should be on server side.

    Regards,

    Rajesh



    ------------------------------
    Rajesh Verma
    ------------------------------