9.10 TeamWorks Site Security

9.10.1 Configuring a Proxy Server

Your Micro Focus TeamWorks system should be located behind your firewall. If TeamWorks users want to access the TeamWorks site from outside your firewall, you should set up a proxy server outside your firewall to provide access.

9.10.2 Setting the TeamWorks Port 8443 Administrator Password

The TeamWorks site is initially installed to allow administrator access by using the user name admin and the password admin. You are prompted to change the TeamWorks administrator password the first time you log in to the Port 8443 TeamWorks Administration Console. Thereafter, you can change the password as described in Modifying Port 8443 Administrator Accounts.

9.10.3 XSS—TeamWorks Is Secure

Cross-site scripting (XSS) is a client-side computer attack that is aimed at web applications. Because XSS attacks can pose a major security threat, Micro Focus TeamWorks contains a built-in security filter that protects against XSS vulnerabilities. This security filter is enabled by default.

What Content Is Not Permitted

By default, the XSS security filter in TeamWorks is very strict, and does not allow users to add certain types of content. For example, the following content is not permitted:

  • HTML that contains JavaScript

  • Forms

  • Frames

  • Objects

  • Applets

Where the Content Is Not Permitted

The type of content discussed in What Content Is Not Permitted is filtered by TeamWorks in the following areas:

  • Text and HTML fields in comments

  • Uploaded HTML files