Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AuthZ: Permit metadata access but deny (some) file access #412

Open
rosiel opened this issue Nov 9, 2016 · 1 comment
Open

AuthZ: Permit metadata access but deny (some) file access #412

rosiel opened this issue Nov 9, 2016 · 1 comment
Labels
Subject: Access Control related to managing roles and permissions/information security. Type: use case proposes a new feature or function for the software using user-first language.

Comments

@rosiel
Copy link
Member

rosiel commented Nov 9, 2016

Title (Goal) Permit metadata access but deny file access
Primary Actor Repository architect
Scope access
Level High
Story I want to "lock down" the full-resolution or full-text or OCR files (formerly datastreams) so that only certain users can access it, but allow other users to view the object's metadata (and perhaps other related files like a thumbnail or low-res image).

Examples:

  • Islandora Scholar Embargo - does this on a timed basis (implemented at UPEI and elsewhere)
  • From Kelsey: "Copyright protected and limited distribution records have XACML policies restricting access to the OBJ datastream to Admin only."
  • "Signature" datastreams - scans of people's signatures and release forms - are not for general consumption.
@rosiel
Copy link
Member Author

rosiel commented Nov 9, 2016

Sorry - I can't label this "Use Case" but if you can, please do!

@ruebot ruebot added the use case label Nov 9, 2016
@kstapelfeldt kstapelfeldt added Type: use case proposes a new feature or function for the software using user-first language. Subject: Access Control related to managing roles and permissions/information security. and removed use case labels Sep 25, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Subject: Access Control related to managing roles and permissions/information security. Type: use case proposes a new feature or function for the software using user-first language.
Projects
Development

No branches or pull requests

3 participants