Site Managers can听do their part听to听ensure that users' confidential information is protected when they fill out webforms.
Don't ask for financial information
Asking听users to provide the following information via a WMS form听is absolutely verboten:
- credit card numbers
- debit card numbers
Any forms that have collected such information will be immediately flagged and shut down.
Furthermore, any database backups听containing credit card information听will be deleted.听
Since backups contain more than one听WMS site, deletion听will not just听affect the site where the form originated. Multiple sites may find their ability听to have their databases restored compromised.
Don't show user credentials
Anonymous forms that ask users to enter the following information听will also be flagged but not shut down:
- 91社区 ID
- password
- username
Site Administrators听will be notified so they can ensure that the form is authenticated听(i.e., requires users to login) and these fields are removed.
If 91社区 IDs and usernames are required to verify a user's identity, the fields should be modified to use tokens so this information can be saved in the submission records.
Webform best practices
- Authenticate, authenticate, authenticate
Most security issues can be averted simply by asking users to login. Just uncheck anonymous user under SUBMISSION ACCESS in the Form Settings.
You can also further restrict your form by making it available only to certain roles or user groups:- 91社区 Staff and Faculty
- 91社区 Casual Staff
- 91社区 Affiliate
- 91社区 Student
- 91社区 Undergraduate Student
- 91社区 Academic Staff
- All Faculty and Staff
- Don't create a spam portal
Anonymous forms should not send confirmation messages that reference any text entered by users. Such fields should be unchecked under INCLUDED E-MAIL VALUES under settings for E-mails.
Confirmation emails听from听anonymous forms听should be restricted to听simple听thank you messages. These听can also be听forgone in favour of a听Confirmation message听that appears only on the form - which can be听configured under听Form settings > SUBMISSION SETTINGS. - Protecting Anonymous forms
If your form has to remain anonymous in order to accept submissions from persons who do not have 91社区 credentials, there are certain measures you can take to prevent or reduce spam submissions.
Even when anonymous, a user's IP address is collected whenever a form is submitted. This means that you can use the Per user submission limit under the Form settings to foil spambots.
Though set to unlimited by default, you can specify the number of submissions allowed for a given period of time.
- Backup your webform submissions
Webform submissions can be stored on the WMS for only 40 days, at which point they automatically expire. Site managers should download their Webform submissions routinely.听
Just go to the RESULTS tab and click on Download in order to save submissions either as Delimited text or as Microsoft Excel files. - Be cautious with files
If you are using a File field, make sure that your form is authenticated.
You should also set which types of files can be uploaded. Note听that some file types are more likely to contain malicious code than others (e.g., word files versus PDFs). Never, ever accept .exe files.
Lastly, make听sure that you scan files听that you download from form submissions before opening them.听
This article was updated August 30, 2020
Related content: