Error when attempting to use links that are of type "file://"

Document ID : KB000103811
Last Modified Date : 27/07/2018
Show Technical Document Details
Issue:
When attempting to create a link of type "file://", it results in an error: "CMN-0016: Attribute 'URL' has an invalid value". For example a user attempts to create application link like the following "file://localnfs/project/etc" as a new link for tasks, they will get an error "CMN-0016: Attribute 'URL' has an invalid value."
Resolution:
This behavior is as expected as PPM does not allow the user to add a URL value without http:// (or https://). This is to prevent Cross Site Scripting vulnerabilities from occurring. This security concern was resolved via DE33311 (S2): Cross Site Scripting (XSS). The file:// protocol was removed as a result of fixing the defect. Engineering is currently reviewing if there is a safe way to enable the file:// protocol in future versions of CA PPM.