Error when attempting to use links that are of type "file://"


Article ID: 103811


Updated On:


Clarity PPM SaaS Clarity PPM On Premise


When attempting to create a link of type "file://", it results in an error: "CMN-0016: Attribute 'URL' has an invalid value". For example a user attempts to create application link like the following "file://localnfs/project/etc" as a new link for tasks, they will get an error "CMN-0016: Attribute 'URL' has an invalid value."


Component: PPMSEC


This behavior is as expected as PPM does not allow the user to add a URL value without http:// (or https://). This is to prevent Cross Site Scripting vulnerabilities from occurring. This security concern was resolved via DE33311 (S2): Cross Site Scripting (XSS). The file:// protocol was removed as a result of fixing the defect. Engineering is currently reviewing if there is a safe way to enable the file:// protocol in future versions of CA PPM.