-
Notifications
You must be signed in to change notification settings - Fork 9
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
introduce whitelist capability for nfs4_setfacl #43
Labels
enhancement
New feature or request
Comments
The curator's username will not show up in the iRODS log file. Possible solutions:
|
SL4J is in there down to the Jargon level so this sort of thing should be
possible!
…On Wed, Sep 25, 2019 at 3:13 PM korydraughn ***@***.***> wrote:
The curator's username will not show up in the iRODS log file.
Possible solutions:
- NFSRODS logs the curator who triggered this in its own log file.
- NFSRODS could use Log4j and send messages directly to rsyslog (could
be pointed to a remote/central logging service).
- NFSRODS could write into a log file in the iRODS logical namespace.
—
You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub
<#43?email_source=notifications&email_token=AAIL4LM7KHTZ7C26GY6PYG3QLOZ5ZA5CNFSM4I2DJK42YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOD7TAU4A#issuecomment-535169648>,
or mute the thread
<https://github.com/notifications/unsubscribe-auth/AAIL4LMOL4TGIITGYR2FEMDQLOZ5ZANCNFSM4I2DJK4Q>
.
|
korydraughn
added a commit
to korydraughn/irods_client_nfsrods
that referenced
this issue
Oct 7, 2019
… to set ACLs on an object.
korydraughn
added a commit
to korydraughn/irods_client_nfsrods
that referenced
this issue
Oct 7, 2019
korydraughn
added a commit
to korydraughn/irods_client_nfsrods
that referenced
this issue
Oct 7, 2019
… to set ACLs on an object.
korydraughn
added a commit
to korydraughn/irods_client_nfsrods
that referenced
this issue
Oct 7, 2019
Server now prints the configuration to the log on startup.
korydraughn
added a commit
that referenced
this issue
Oct 8, 2019
Server now prints the configuration to the log on startup.
korydraughn
added a commit
to korydraughn/irods_client_nfsrods
that referenced
this issue
Oct 8, 2019
korydraughn
added a commit
to korydraughn/irods_client_nfsrods
that referenced
this issue
Oct 8, 2019
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
This feature would introduce a whitelist defined via metadata on users and groups.
If a user is in the whitelist or in a group in the whitelist, they would be able to run
nfs4_setfacl
on the specified logical path or any collection or object 'below' it, regardless of their own permissions on that collection or object.Use Case
Data within a double-blind study should not be visible by the curators of the system. However, in order to allow others to see the data, the curators need to be able to set permissions. This set of curators would be defined by a search in the catalog of users or groups with the following attached AVU:
Note
If this is implemented by calling 'change permissions' as the NFSRODS
proxy_admin_account
, then we need to confirm whether the curator's username appears in the server (and therefore in any audit logging).The text was updated successfully, but these errors were encountered: