✔ Changes to user account archiving system - HIGH PRIORITY
Completed by Morgan M.
- Assigned to
-
Anil V.
Harsh P.
- Due on
- Notes
-
Further to the video below, there are a number of changes that need to be made to user account archiving system on the subscriber management system: https://www.investorstatelawguide.com/Subscribers/Index. Note that I have set the deadline on this to-do for May 21st, because these changes need to implemented on www.islg before the May 25th GDPR deadline. The following changes need to be implemented:
- Add (2) "Delete All", (2) selection "Delete" and "De-archive" options to to the top of the archive section of the subscriber management page: https://www.investorstatelawguide.com/subscribers/index?expand=1#abc
- Ensure that all the data displayed in the main subscriber management section is displayed for archived users section, particularly "last active". Also, ensure the column headings line-up with the appropriate data in the table.
- Remove Notepad Details from archive user section, and take necessary steps to ensure Notepad Details data is inaccessible to all admin users and developers. This should be stored on an inaccessible part of the server, and we should look into method for encrypting the data in the event of a data breach.
- Ensure that when a user account is deleted through the archive section, it is permanently deleted from the server. Also, we'll need to ensure that we perform monthly syncs between dev.islg and www.islg to ensure data is properly deleted from all environments.
Please put a high priority on completing this to-do.
Similar to the subscriber management changes, these are requirements we need in place before the end of next week. Please confirm work has begun.
Thanks,
Morgan
We are working on this task and will update you soon.
Morgan
This task is done and uploaded on dev.islg. Please check and let us know the feedback.
The changes look good on dev.islg. However, I just realized that we should probably schedule the migration on Tuesday since
Thanks,
Morgan
This task has migrated on www.islg. We do not test the Delete and Delete All functionality on www.islg. so, Please check and let us know the feedback.
The Notepad link is now gone, however, I don't have a link saved to make sure that visiting the notepad details through a direct URL.
Thanks!
Ryan
The migrated changes for the archiving system on www.islg look good. Re
Also, as we discussed this morning, we'll start work on encrypting the Notepad data on a separate SQL database, but I'll create a separate to-do for this task.
Thanks,
Morgan
We have tested above scenario and it works fine. Currently, We have given permission only to following admin user to access the direct URL for Notepad details.
Admin User : mmaguire
For Example,
Note : For tracking the Notepad Details directly through URL, You should have to enter the userid at the end of URL (As shown in above URL)
Please check and confirm.
I'll let
Only the client user should be able to see their notepad details through the front-end.
Thanks!
Ryan
Please suggest.
I am confirming
Note that this is separate from the Notepad session details, which will be accessible to admin users as they currently are.
Thanks,
Morgan
We have removed permission to direct access URL for Notepad details from all admin users on both dev.islg and www.islg.
Please check and confirm.
I've attempted to access https://www.investorstatelawguide.com/subscribers/UserTrackingDetail?userid=3010 and http://dev.investorstatelawguide.com/subscribers/UserTrackingDetail?userid=3010 and received no data as expected.
Ryan
Morgan