1.16 Security Issues

1.16.1 Logout Does Not Happen When Filr Is Accessed Directly and Is Fronted by Access Manager

When Filr is fronted by NetIQ Access Manager, only the Filr administrator is able to access Filr directly. When Filr is accessed directly in this configuration, simultaneous logout for the Filr system is not successful.

After the Filr administrator logs in directly to Filr (and Filr is configured with Access Manager), all browser sessions should be immediately closed to ensure logout.

1.16.2 External Users Can Search for and View Internal Users

When an external users accesses the Filr site (either as the Guest user or with an external user account), the external user can use the Filr Search functionality to search for any user in the Filr system. External users can search on usernames or information in the user profile, such as the domain of an email address.

Novell sees this as an undesirable effect and plans to address this issue in a future release.

For more information about external users, see Allowing External Users Access to Your Filr Site in the Novell Filr 1.0.1 Administration Guide.

For more information about performing a search in Filr, see Searching for Information in the Novell Filr 1.0.1 Web Application User Guide.