Security

Blog
Security
Saturday, December 29, 2018PrintSubscribe
Access Control List and “Local” Dates

Code On Time release 8.7.7.0 introduces the permission-based application configuration based on Access Control List. This feature is unique to applications created with Unlimited Edition. Next release of the app generator will introduce permission matrix  and permission builder to allow runtime configuration of live applications with ACL.

Release 8.7.7.0 also enabled local time zone presentation of date values stored in UTC format.

The following features and bug fixes are also introduces in this release:

  • (App Gen) Files with ProjectName\Services\ApplicationServices.* and ProjectName\Services\EnterpriseApplicationServices.* patterns are not deleted in projects with the framework in the class library when the project is re-generated.
  • (Touch UI) My Account option is displayed in *.aspx projects.
  • (Framework) ASPX projects turn-off combined/compressed scripts when the app running in debug mode from Visual Studio.
  • (Framework) Blob file name is stored in the database at the time of BLOB value submission if the matching "FileName" field is not automatically detected on the client.
  • (Framework) Blob handler validates read-access for blob fields by confirmation that the user can “see” the table row corresponding to the specified primary key. It also ensures that the particular BLOB field is also "visible" to the user and was not removed through virtualization of the controller.
  • (Framework) Prevented XPath injection attack errors reported by BURPSUITE Professional. Please note that testing methods would not have allowed to exploit the app framework.
  • (Framework) Absolute URIs are being used in script reference to appservices, __baseUrl, and __serviceUrl,
  • (Touch UI) Pages without content display a site map relative to the page.
  • (Project Designer) Dragging of field on a category will remove the corresponding data field from other categories of the same view.
  • (Touch UI) Bootstrap is correctly linked to pages in Premium edition.
  • (Touch UI)  Fixed. Tap on “more” button in child data view will select the row when multiple selection is enabled.
  • (Touch UI) Conditional Action Bar actions correctly respond to the changes in the values of the selected row with and without multiple selection.
  • (Client Library) Added caching of compiled functions to speed-up dynamic expressions.
  • (Touch UI) Only forms cache the current command row as "edit row".
  • (Touch UI) Switching of active tab performs full page resize.
  • (Client Framework) Added support for second-generation Grid/Cards/List.
  • (Framework) Fixed incorrect NullValue label in Classic UI.
  • (Model Builder) Single quotes in the name of the table will not cause exceptions displayed when models are rendered.
  • (Model Builder) Calculated fields created in Model Builder are not marked as "hidden" in the views of a data controller.
  • (Framework) Method AlterControllerWith handles parameters of methods wrapped in single quotes.
  • (Wizard) Tabs adjust their height when the window size is changed.
  • (Wizard) Models and Entities without Models take up the entire height of the page.
  • (Framework) Fixed "Key not found" in one-to-one entity processing causes by unmapped changed fields up the hierarchy of the relationships.
  • Fixed the "font" and "image" references in combined stylesheet that were not compatible with modern firewalls.
  • (Touch UI) Woff fonts are now returned with a static mime type "application/font-woff".
  • (Framework) Fixed incorrect parsing of "end-of-text" terminator in controller customization rules.
  • (App Gen) Option autoEventWireup is now set to "true" in ~/Config/CodeOnTime.CodeDom.xml.
  • (Designer) Assigned Data Text Field to Field lookup on Data Fields to fix issue where field is shown as empty
  • Removed allow nulls=false from Flat Rendering on Action Groups to ensure that user can save the action group if the field is hidden
  • (Touch UI) Event 'scrollablepageready.app' is triggered just before the transition to the active page. This allows the Grid 2.0 to render itself.
  • (Framework) Method ApplicationServices.ValidateToken will not fail when decrypted invalid token and will return "false" when this happens.
  • (Framework) Optimization o f "left join" to "inner join" is performed when access control rules are engaged.
  • (Framework) A dedicated connection is created for every Batch Edit or Delete to ensure that optional transactions do not include the entire set of selected records.
  • (Framework) The processing loop of custom actions can be interrupted by calling PreventDefault(true).
  • (Framework) Fixed transactional processing of 1-to-1 entities and many-to-many fields.
  • Exception during the loading faze of Azure publishing wizard.
  • (Touch UI) If the data view field has the parent form whose parent is not configured to have the same controller the parent form is chosen as the parent data view.
Monday, November 26, 2018PrintSubscribe
Limit Access For Particular User Name

Let’s say you want to prevent a user with a certain name from being able to access your app pages.

Application framework provides a centralized method of content retrieval, which makes possible creative ways of content production at runtime. You can produce a custom output for the user with the name mark no matter what page he is trying to access.

If the user with the name mark is logged in then he will be presented with the following message on any application page.

Data Aquarium application framework allows dynamic manipulation and substituion of the content returned by the app to the end user.

Create a code file in ~/custom folder of your app.

Custom code file in the app created with Code On Time.

Enter the following definition of partial class ApplicationServices.

using System.Collections.Generic;
using System.Web;

namespace MyCompany.Services
{
    public partial class ApplicationServices 
    {
        public override void LoadContent(HttpRequest request, HttpResponse response, 
            SortedDictionary<string, string> content)
        {
            // Let the framework to load the file from the file system.
            // Typically the content will be retrieved from ~/app/pages folder.
            base.LoadContent(request, response, content);
            if (content.ContainsKey("File"))
            {
                // The framework has located a physical file, let's check the user identity.
                var identity = HttpContext.Current.User.Identity;
                if (identity.IsAuthenticated && identity.Name == "mark")
                {
                    // remove the original file to prevent any default parsing of its contents
                    content.Remove("File");
                    // simulate the result of parsing by providing Title and Content of the page.
                    content["PageTitle"] = "Mark, go away";
                    content["PageContent"] =
                        "<div data-app-role=\"page\">" +
                        "<h1>Mark has no access!</h1>" +
                        "<p>Please log out or close the browser!</p>" +
                        "</div>";
                }
            }
        }
    }
}

An authenticated user with a name other than mark will see the application pages as defined at design time.

A data page in the app created with Code On Time app builder.

Thursday, October 26, 2017PrintSubscribe
User Pictures in SharePoint, Facebook, Google

Release 8.6.7.0 introduces automatic capturing of user profile picture for Facebook, Google, and SharePoint accounts when configured for Single Sign-On with OAuth. The user picture is captured directly from the identity provide and stored in the CMS of the app.

We have corrected the latest iteration of themes to re-enable conditional styling rules. Just make sure to place your CSS rules into ~/css folder instead of ~/touch.

image

The release aslo corrects muscellaneous issues related to the introduction of the new file structure compatible with the upcoming native apps. See the details below.

  • Restored modal-never tag function to force fullscreen presentation even when modal forms are allowed by the screen size.
  • Summary in the sidebar does not display NULL values anymore.
  • Fixed. If Int field has Text values in Items then advanced search must be configured as text. Previously the lookups were displayed as simple “numeric” values.
  • Lookups with static context field values (e.g. "CategoryName='Condiments'" or "CategoryID=1, CategoryID=5") do not expose them in the filter that can be cleared. Also the specified fields are hidden in the filtered view. This reproduces the behavior of the Classic UI.
  • Static lookup fields with Context dependencies will first cause Calculate if defined and then popuplate the list of values. Previously items stopped being populated.
  • Actions in "Custom" group are rendered as "hidden" if defined in the view layout but not available in the controller in Touch UI apps.
  • Automatically created row of "Custom" actions is removed when there are no "visible" custom actions in Touch UI apps.
  • “Form Layout” feature in Developer Toolbar of Touch UI apps correctly pre-selects the current page size for the layouts available for download.
  • Calendar view style correctly displays tabs making possible interactive selection of Day/Week/Months/Year/Agenda mode.
  • Resolved the bug with “Controller not found.” when ~/controllers folder is spelled in camel notation.
  • SharePoint OAuth now downloads user profile photo if supported.
  • Fixed - Blob fields marked as "required" will allow submitting a form. Physical BLOB  columns in tables must allow NULL values for apps to allow uploading of large content. Developers can mark BLOB fields are required to force a submition when the record is created.
  • Facebook OAuth now supports download of profile picture.
  • Fixed issue with "Sync Roles" showing true in oauth wizard.
  • Google OAuth provider now downloads user avatar.
  • Fixed issues with Web App Factory publishing.
  • Files daf-resources.js and daf-resources.min.js are now removed from ~/js/sys folder, since these files are not needed for an application to execute correctly. Only the localized versions of these files will remain in the project.
  • Fixed issue where ASPX projects adding an account would navigate to "login" instead of "login.aspx".
  • Removed "Sign Up" and "Forgot Password" if Active Directory is enabled in Membership and Autentication Settings.
  • Included images & fonts in Web App Factory. Fixed regression when js folder does not exist.
  • Toolbar located at the bottom of the sidebar will become hidden if there are no icons displayed in it.
  • Model Builder - Duplicate model field names are not created when columns are borrowed from the master tables joined in the model query.
  • Ensured duplicate site content is not created if model exists with name "SiteContent".
  • Removed legacy rules app-icon-check to prevent interferance with the ui-btn::after in the grid/list/cards.
  • Ensured bootstrap CSS link in Classic projects is formed correctly.
  • Disabled Native App SUpport for ASPX projects.
  • Removed unused references to AJAX framework script resolution.
  • Fixed issue with OAuth registration - adding system identity no longer sets content type to "application/octet-stream".
  • Ensured that Active Directory authentication configuration will cause the login button to display.
  • Fixed issue with Web App VB not including culture JS files in assembly.
  • Fixed compilation issues of GetManifestFileServiceRequestHandler when implemented in Visual Basic.
  • Removes remaining references to Sandbox project created in WebApp Factory projects.
  • Fixed issue with Localizer JavaScript encoding values in controls.