How to Only Allow Admin to view result
Last Post 08-26-2013 07:03 AM by Ryan Bakerink. 5 Replies.
AddThis - Bookmarking and Sharing Button
Author Messages Not Resolved
ZhenUser is Offline
new to the springs
new to the springs
Posts:3
Avatar

--
08-23-2013 12:13 PM
    Hi. I purchased dynamic form and love its powerful functions. 

    I am setting up a class registration form and add the view result link to the form completion email sent to the class administrator. Therefore, when a registration received, the student admin can click the link and review the result in a web browser. 

    I set administrator as View Results Security Role:.  However, when I click the link in the email, url likei ".../tabid/338/Mode/ViewResults/ViewID/ef0d4786-4a43-4f0a-8c8b-544f41bfd6b5/Default.aspx", the page shows up without requiring login as an admin. Therefore, everyone on the internet can view the submitted form if he knows the link.

    This brings a security risk. Is there any way I can set up to only allow administrator to view the submit result?

    Thanks a lot.

    Zhen
    CandaceUser is Offline
    river guide
    river guide
    Posts:2431
    Avatar

    --
    08-23-2013 12:32 PM
    Hi Zhen,

    Yes, that would be a concern. Can you please confirm that you are on the latest version which is DF 4.1.40? If not, what is the module version you're using?

    Thanks!
    Candace
    ZhenUser is Offline
    new to the springs
    new to the springs
    Posts:3
    Avatar

    --
    08-23-2013 12:39 PM
    Yes, I have 4.10.4 version. I am working on the development server now and haven't activated it yet.
    CandaceUser is Offline
    river guide
    river guide
    Posts:2431
    Avatar

    --
    08-23-2013 12:45 PM
    Thanks. The unauthorized user will need to know the exact GUID for the specific form submission to view it as a link. However, I do believe this should require login, as you mentioned. Let me send this up to our developers for review.

    What DNN version are you on?

    ZhenUser is Offline
    new to the springs
    new to the springs
    Posts:3
    Avatar

    --
    08-23-2013 12:54 PM
    We are using DNN7.

    I understand it requires the GUID. However, the registration form contain sensitive information and we want to make sure it is secured.
    Ryan BakerinkUser is Offline
    river guide
    river guide
    Posts:1900
    Avatar

    --
    08-26-2013 07:03 AM
    Hello Zhen,

    Then the best recommendation may be to disable the availability of the View form results and to use a reporting tool to review this information on another page. That way you can control the Permissions to the page and the module.

    Dynamic Views is a great tool that can pull results from a Dynamic Form instance. You can easily configure a Dynamic View within 10-15 minutes.

    You can download a trial version of Dynamic Views from here:
    http://www.datasprings.com/products...iews-trial

    Give the trial a test run(it's free to do so), and I think you'll be happy to find out the flexibility of Dynamic Views versus the Dynamic Forms View Form Results feature.

    Let us know if you have any questions.

    Thanks,

    Ryan


    ---
  • film izle
  • 720 izle
  • film
  • sinema izle
  • film makinesi
  • T�rk�e dublaj film
  • film izle
  • film izle
  • baglan film izle
  • sinema izle
  • 1080 film izle
  • film mercegi