-
Notifications
You must be signed in to change notification settings - Fork 27
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
SDS club view not working #793
Comments
Bruce is looking in to this. |
What SDS role does the user have? In order to access the sensitive data for record https://biocache.ala.org.au/occurrences/6f987032-aa50-4be2-aa5c-0ec34fa4ac96 the user would need Below is the Location data with |
Thanks for looking at that Bruce, I've got it with that role - I didn't have the WA role and didn't think to check a different state. I thought that ALA admin users were able to see everything. It's better if it's this way though. Can close this. |
Reading the contents of Bruce's screenshot above, it looks like the page needs to be in view Club View as well AND have the correct SDS role... Club view AFIK is only available for |
Ah yes, I don't have a spare non-admin user to test that with |
The club view in bicache-hub is trigger based on the role defined in the application config property The sensitive data is returned from biocache-service for authenticated users.
if the occurrence matched this then sensitive data is display. Currently It may be possible to add an extra mapping to biocache-service
should allow access to all sensitive data |
Just for my reference and FYI @TaniaGLaity Sorry Bruce, don't understand this?
So ROLE_ADMIN has Club View |
Found another issue around SDS views: the occurrenceRemarks field should be hidden in sensitive views. It looks like in this record, the SDS has wiped the value from the occurrenceRemarks field in the processed value, but the raw value is still publicly exposed. |
Add |
In both biocache-test and biocache, I can't see the correct raw (preprocessed sensitive) values for the location. Concern that people with SDS role acceess to records can't access them.
Same record in biocache and biocache-databox
https://biocache-databox.ala.org.au/occurrences/81e82216-7b31-4af1-b840-9a6cbc784d83 https://biocache.ala.org.au/occurrences/6f987032-aa50-4be2-aa5c-0ec34fa4ac96
Reported by @peggynewman (cc: @sughics and @brucehyslop )
The text was updated successfully, but these errors were encountered: