Skip to content
This repository has been archived by the owner on Sep 12, 2023. It is now read-only.

Hyrax - Check that RIIIF requests comply with access control #32

Open
cudevmaxwell opened this issue Jan 9, 2019 · 3 comments
Open
Labels
Milestone

Comments

@cudevmaxwell
Copy link
Collaborator

For example, if an image is locked down to institutional or private access, the image should not be available through RIIIF to the public.

@cudevmaxwell cudevmaxwell added bug Something isn't working needs testing labels Jan 9, 2019
@cudevmaxwell cudevmaxwell added this to the Beta Release milestone Jan 9, 2019
@cudevmaxwell
Copy link
Collaborator Author

I'd like confirmation from @orangewolf that this is resolved. I'll also double check.

@orangewolf
Copy link
Contributor

@cudevmaxwell yes, a double check is always a good idea. I know the product owner for Hyku (some bloke named @orangewolf) and we'd consider it a pretty big bug if permissions were not checked in RIIIF ;-)

@orangewolf
Copy link
Contributor

I've confirmed this by trying to access private images by accessing their full path. Neither manifests or images can be accessed

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

2 participants