As RESTful suggests, the GET request will always have the primary key in the URL like: http://somesite.com/somecontroller/123/edit
In the app we have role based access and only admins have access to edit. We made sure that the application is protected and only admins can update an existing record. The so called Security had a different perspective. They were not willing to expose the id(=123). The solution was to encrypt the id.
I came across a good blog here.
Following the same concept:
- I added a EncryptDecryptHelper module inside my lib directory. The module has 2 methods.
- encrypt -> used OpenSSl Cipher RC4 digest and Base64 encoding of the string for an already defined KEY and IV
- decrypt -> used the same KEY and IV to decode the string
- Included the module inside my model and over-ride to_param to encrypt the primary key.
- Added a before filter method on the application controller to decrypt the primary key.Made sure we are passing objects instead of id while creating links eg:-
- Do:
<%= link_to 'city', :controller=>'cities',:action=>'show',:id => @city %>
Instead of:
<%= link_to 'city', :controller=>'cities',:action=>'show',:id => @city.id %>
The security team is happy now.
No comments:
Post a Comment