Uploaded image for project: 'SEAD'
  1. SEAD
  2. SEAD-501

Map web services to specific permissions

XMLWordPrintableJSON

    • Icon: Task Task
    • Resolution: Fixed
    • Icon: Minor Minor
    • 1.5
    • None
    • None
    • None

      Many web service operations mirror those in the GUI and could use the same permissions, rather than all defaulting to 'remote api' permissions. This task is to review the permissions and services and add an appropriate permission check. The new dataset and collection services all identify the user and test access control already, so checking permissions should be incremental, assuming there's a matching permission. Some flexible services, e.g. the SPARQL service, might remain with the remote api permission (or similar) with the possibility of only allowing admins/power users and/or privileged apps to access them - moving the other services off to other permissions will make it easier to restrict these.

              jimmyers Jim Myers
              jimmyers Jim Myers
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: