<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Excel Report Template Security]]></title><description><![CDATA[<p dir="auto">Hello all,<br />
First of all here are my system specs:<br />
Mango Core: 3.5.6<br />
Mango API: 3.5.2<br />
Mango UI: 3.5.5<br />
Platform: Centos 7.4.1708<br />
Java Version: 1.8.0_161</p>
<p dir="auto">One of our users have pointed out an issue with the file store for the Excel Report Templates. When one user is logged in and creates an excel report they can see everyone's templates in the folder. This is a data protection issue since the templates usually have the users name and site name in the title of the template.</p>
<p dir="auto">For example a user is logged in and would like to set up a new Excel report:<br />
<img src="https://camo.nodebb.org/be2064d3e4f4dd57dab7bfb69b515fd9a68ece0d?url=https%3A%2F%2Fi.imgur.com%2Fe2yKEJu.png" alt="0_1560340279163_fba40cc6-27fa-499a-82b3-e608f13798d1-image.png" class=" img-fluid img-markdown" /><br />
The reports from other users are not visible and that is great. but when they go to choose a file:</p>
<p dir="auto"><img src="https://camo.nodebb.org/e72aa4c8d94b96cee98dee0c836592cc81f7880d?url=https%3A%2F%2Fi.imgur.com%2FgmOnvrx.png" alt="0_1560340770231_17d6aea1-9b19-4474-9a10-a70c885dc435-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">All the other user files are visible.</p>
<p dir="auto">I can't see anywhere in the system that allows me to put passwords on the templates to prevent this from happening.</p>
<p dir="auto">Is there anywhere in the background that I could add permissions to stop users from seeing other templates that do not belong to them?</p>
<p dir="auto">Cheers</p>
<p dir="auto">Brian</p>
<p dir="auto">p.s. I just checked the way the reports worked in mango 2.8. This is not an issue because the choose file button only gives the user the ability to browse their own local drives.</p>
]]></description><link>https://forum.mango-os.com/topic/4251/excel-report-template-security</link><generator>RSS for Node</generator><lastBuildDate>Tue, 19 May 2026 13:25:31 GMT</lastBuildDate><atom:link href="https://forum.mango-os.com/topic/4251.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 12 Jun 2019 11:49:35 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Excel Report Template Security on Wed, 19 Jun 2019 08:43:12 GMT]]></title><description><![CDATA[<p dir="auto">Hello Phil,<br />
Thank you for the update. In the mean time I will have to anonymise the spreadsheet templates.</p>
<p dir="auto">Cheers</p>
<p dir="auto">Brian</p>
]]></description><link>https://forum.mango-os.com/post/22445</link><guid isPermaLink="true">https://forum.mango-os.com/post/22445</guid><dc:creator><![CDATA[BG]]></dc:creator><pubDate>Wed, 19 Jun 2019 08:43:12 GMT</pubDate></item><item><title><![CDATA[Reply to Excel Report Template Security on Tue, 18 Jun 2019 17:02:21 GMT]]></title><description><![CDATA[<p dir="auto">Hi Brian,</p>
<p dir="auto">I do not believe a fix for this observation is in that beta. I do believe it is our intention to make that fix. The timeline of the release is not firmly established. I will update you when a fix for the issue is in the code, and when it is released.</p>
]]></description><link>https://forum.mango-os.com/post/22441</link><guid isPermaLink="true">https://forum.mango-os.com/post/22441</guid><dc:creator><![CDATA[phildunlap]]></dc:creator><pubDate>Tue, 18 Jun 2019 17:02:21 GMT</pubDate></item><item><title><![CDATA[Reply to Excel Report Template Security on Tue, 18 Jun 2019 07:57:08 GMT]]></title><description><![CDATA[<p dir="auto">Hello IAS,<br />
I just saw the forum entry for the changes made to the modules for 3.6 beta 6.<br />
I think some of those changes are addressing my concerns here.<br />
How soon can I expect the beta to become a general release?</p>
<p dir="auto">Cheers</p>
<p dir="auto">Brian</p>
]]></description><link>https://forum.mango-os.com/post/22439</link><guid isPermaLink="true">https://forum.mango-os.com/post/22439</guid><dc:creator><![CDATA[BG]]></dc:creator><pubDate>Tue, 18 Jun 2019 07:57:08 GMT</pubDate></item><item><title><![CDATA[Reply to Excel Report Template Security on Mon, 17 Jun 2019 10:33:06 GMT]]></title><description><![CDATA[<p dir="auto">Bump.</p>
<p dir="auto">I am eager to get a solution to this issue which has become a problem for us.</p>
<p dir="auto">Thank you</p>
<p dir="auto">Brian</p>
]]></description><link>https://forum.mango-os.com/post/22433</link><guid isPermaLink="true">https://forum.mango-os.com/post/22433</guid><dc:creator><![CDATA[BG]]></dc:creator><pubDate>Mon, 17 Jun 2019 10:33:06 GMT</pubDate></item><item><title><![CDATA[Reply to Excel Report Template Security on Wed, 12 Jun 2019 15:05:00 GMT]]></title><description><![CDATA[<p dir="auto">Hello,<br />
I was trying several permission variations and removed read permission to the entire filestore. The result was that I lost the logos and other image files that were uploaded for the dashboards but there was no change to the excel reports filestore for some reason. Each user was still able to see everyone's templates.</p>
<p dir="auto">Cheers</p>
<p dir="auto">Brian</p>
]]></description><link>https://forum.mango-os.com/post/22402</link><guid isPermaLink="true">https://forum.mango-os.com/post/22402</guid><dc:creator><![CDATA[BG]]></dc:creator><pubDate>Wed, 12 Jun 2019 15:05:00 GMT</pubDate></item><item><title><![CDATA[Reply to Excel Report Template Security on Wed, 12 Jun 2019 14:36:38 GMT]]></title><description><![CDATA[<p dir="auto">I don't believe this is possible at the moment but I might be wrong but it sure does seem like a feature worth having!</p>
]]></description><link>https://forum.mango-os.com/post/22399</link><guid isPermaLink="true">https://forum.mango-os.com/post/22399</guid><dc:creator><![CDATA[CraigWeb]]></dc:creator><pubDate>Wed, 12 Jun 2019 14:36:38 GMT</pubDate></item></channel></rss>