Project

General

Profile

Actions

Epic #51

open

Security Points Checking

Added by rashmita rout about 1 month ago. Updated about 1 month ago.

Status:
New
Priority:
Medium
Assignee:
-
Target version:
-
Start date:
01/05/2026
Due date:
% Done:

0%

Estimated time:
(Total: 0:00 h)
Work Type:
Platform
Technical Area:
Release Narrative:

Description

1. Clickjacking:-
Preventing the browser from loading the page in frame using
the X-Frame-Options or Content Security Policy (frameancestors) HTTP headers.

2. Clear text password submission:-
Ensure that user passwords are never transmitted, processed, or stored in cleartext by enforcing strong cryptographic hashing, encrypted transport, and secure cookie handling

3. Improper Error handling:-
Prevent leakage of internal system details through error messages.

customizing error messages with limited information strikes a balance between informing users about issues and maintaining a user-friendly interface, all while safeguarding sensitive technical details.

Disabling or limiting detailed error handling involves configuring a system to refrain from displaying intricate technical information, such as debug information, stack traces, or file paths, to end users.

4. Lack Of Security Header:-
Implement security headers such as X-XSS-Protection,
Content-Security-Policy, Referrer Policy, X-Content-TypeOptions, Permiss+D6+D32

5. Server Banner disclouser:-
Hide Server version details as they should not be displayed in
the application response.
Additionally, remove X-Powered by header as it discloses the
software or technology that the server is running.

6. Prevent Unauthorized access to pages-Protected Routes.
Only authorized users can access protected pages
Unauthorized users are blocked or redirected
Protection exists at UI routing + backend API level
No sensitive content is exposed via direct URL, cache, or browser history

7.Enforce Safe UI Behavior.
When a user opens the app for the first time or without explicit permission, the UI should:
Start in least-privileged state
Require explicit user action to enable access
Hide or disable sensitive features

8. Prevent duplicate actions-Form submission control
When a form is submitted:
The Submit button becomes disabled
Only one API request is sent
Duplicate submissions are prevented
Button re-enables only after response


Subtasks 15 (15 open0 closed)

Story #34: Improper Error HandlingNew01/05/2026

Actions
Story #35: Lack of Security HeadersNew01/13/2026

Actions
Bug #54: Missing HTTP Security Headers (CSP, X-Content-Type-Options, Referrer-Policy, X-XSS-Protection)NewTingg Operation01/13/2026

Actions
Story #42: Server Banner DisclosureNewTingg Operation01/13/2026

Actions
Bug #55: Server Banner Disclosure via HTTP Response HeadersNewTingg Operation01/13/2026

Actions
Story #43: Cleartext Password Submission PreventionNew01/05/2026

Actions
Story #52: ClickjackingNew01/13/2026

Actions
Bug #53: Clickjacking Vulnerability – Missing X-Frame-Options / CSP HeadersNewTingg Operation01/13/2026

Actions
Story #58: Prevent unauthorized access to pages-Protected RoutesNew01/19/2026

Actions
Bug #59: Enforce protected routes for authenticated / authorized users only-Back Button / Cache TestNewSuman dobriyal01/19/2026

Actions
Story #60: Enforce safe UI behaviorNew01/19/2026

Actions
Bug #61: A user must not access restricted pages or actions by directly manipulating the URL,NewSuman dobriyal01/19/2026

Actions
Bug #62: Ensure UI restrictions are enforced by backend authorization, not just hidden/disabled on the frontend.NewSandip Gupta01/19/2026

Actions
Story #63: Prevent duplicate actions-Form Submission ControlNew01/19/2026

Actions
Bug #64: Multiple Api request are showing on clicking of save button multiple times. Save button should be disable after a single click.NewSuman dobriyal01/19/2026

Actions
Actions #1

Updated by rashmita rout about 1 month ago

  • Subtask #52 added
Actions #2

Updated by rashmita rout about 1 month ago

  • Description updated (diff)
Actions #3

Updated by rashmita rout about 1 month ago

  • Subtask #43 added
Actions #4

Updated by rashmita rout about 1 month ago

  • Description updated (diff)
Actions #5

Updated by rashmita rout about 1 month ago

  • Description updated (diff)
Actions #6

Updated by rashmita rout about 1 month ago

  • Subtask #34 added
Actions #7

Updated by rashmita rout about 1 month ago

  • Subtask #35 added
Actions #8

Updated by rashmita rout about 1 month ago

  • Description updated (diff)
Actions #9

Updated by rashmita rout about 1 month ago

  • Subtask #54 added
Actions #10

Updated by rashmita rout about 1 month ago

  • Subtask deleted (#54)
Actions #11

Updated by rashmita rout about 1 month ago

  • Description updated (diff)
Actions #12

Updated by rashmita rout about 1 month ago

  • Subtask #42 added
Actions #13

Updated by rashmita rout about 1 month ago

  • Subtask #58 added
Actions #14

Updated by rashmita rout about 1 month ago

  • Description updated (diff)
Actions #15

Updated by rashmita rout about 1 month ago

  • Subtask #60 added
Actions #16

Updated by rashmita rout about 1 month ago

  • Description updated (diff)
Actions #17

Updated by rashmita rout about 1 month ago

  • Subtask #63 added
Actions #18

Updated by rashmita rout about 1 month ago

  • Description updated (diff)
Actions

Also available in: Atom PDF