2 ms·
I am DocuSign’s Lead Developer Evangelist. Thanks to Joseph (OP) for writing this up and to everyone who has contributed to this thread including both the posit
by larrykluger 8y ago
I am DocuSign’s Lead Developer Evangelist.
Thanks to Joseph (OP) for writing this up and to everyone who has contributed to this thread including both the positive and negative comments about integrating with DocuSign.
The problem OP ran into is really one of documentation and not a bug or security issue.
I agree that our docs for the embedded sender view should clearly state that the method’s URL gives full access to the sender’s account, and we’ll fix that ASAP. As others have commented, the assumption of this API method is that each sender has their own account. I also agree that the OP’s use case, which requires that the sender view’s capabilities be strictly limited to the current envelope, is valid. It is under consideration for our roadmap.
A workaround: I recommend that API applications complete the sending process programmatically including document tagging, etc. This also provides the best user experience for the sender.
We actively monitor and reply to the “docusignapi” tag on StackOverflow (I’m “Larry K”), if you want to reach out to us there.
- justinclift 8y ago> The problem OP ran into is really one of documentation and not a bug or security issue. Thanks for admitting fault. How about: a) Refunding them, as they requested. b) Creating a follow up post and submitting here to HN when the docs are actually fixed. After all, the article itself describes many instances of them being told things would be fixed. Your doing so here on HN will be regarded the same way. eg by actions rather than words
- treis 8y ago>The problem OP ran into is really one of documentation and not a bug or security issue. I'm confused about this. If I am given a link for a DocuSign I can gain access to the sender's account by refreshing the page?
- jessaustin 8y agoI also agree that the OP’s use case, which requires that the sender view’s capabilities be strictly limited to the current envelope, is valid. It is under consideration for our roadmap. If this case is valid, other customers besides OP are doing the same thing. They probably have the same vulnerability. It's also not clear how document tagging can stop this hole. If there is just one user then that user's users can't have that user's creds. Rather they must be limited to specific tokens that give them access to their specific documents.