Company: Link Technologies
Case No: L09535. Project: 10.10: LinkSOFT Version 10.1
Logged By: Alvis (Link Technologies) on 27 Aug 2018 02:03PM
Priority: High
Product: Payroll & HR
Group: Enhancement
Time Taken: 2.00 (Weight: 2.00)
Version: 10.155.0117
Assigned To: Development
Circulation: Alvis, Development, Sanjay
Resolve By: Monday, 27 August 2018 12:00 AM [2062 days since logged date]
Status: Closed
Subject: Automatic creation of ESS employee profile
Summary:    

ESS employee profile is currently created by a background process which bypasses the security framework.

This process is insecure because the security question and answer is blank and the user is automatically approved.

To resolve this issue, the following changes will be made:

  1. Add a utility option to "Create Web Login" which will prompt a username and display the registered email address.
    1. Call the security framework to create the user if the user does not exist. The security framework will send an email similar to the new user registered.
    2. If the user exists, all fields are read only.
  2. When an employee profile is saved, call the security framework passing details. 
    1. Details include active/inactive which will approve/disapprove the employee.
    2. Email address
    3. Phone number
    4. Employee Name
  3. Remove the configuration for ESS username format.
  4. Remove the background process that creates employee profile in ESS.

Functionality consideration:

  1. Upload of an employee will create the employee profile without the ESS login. Administrators will have to manually create the ESS profile and link the employee.
  2. If the web login username is blank, the web user profile will not be created.
Audit Notes:Edited by sanjay on 05/03/19 09:21. 
27 Aug 201802:03PM Comment 1 by Alvis (Link Technologies) Case 9535 added to project 09.5
27 Aug 201802:29PM Comment 2 by Sanjay (Link Technologies) Assigned To: Development Followup Date: 27-08-2018 02:29 PM Time Taken: 2.00

The current process is as follows:

  1. Employee profile is created with random encrypted password and Salt
  2. The user has to recover the password. This is sent to their registered email address.
  3. The user then logs in and changes the password and enters their security question and answer.



09 Oct 201908:14AM Comment 3 by Sanjay (Link Technologies) Quality control status: Pass. QC Not required - This case was created before quality check was implemented in version 11 on 30/06/2019
If you have any queries regarding this support incident, please email admin@linktechnologies.com.au and include the Case No: L09535 in the subject line of all emails regarding this issue.

Document size: 1.7 KB
For call complaints, please contact the Managing Director of the company using this form