Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Hub Administrator Managing Access token store #1228

Closed
rpaw053 opened this issue Jan 23, 2017 · 4 comments
Closed

Hub Administrator Managing Access token store #1228

rpaw053 opened this issue Jan 23, 2017 · 4 comments

Comments

@rpaw053
Copy link
Member

rpaw053 commented Jan 23, 2017

As a Hub Administrator, I want to manage privileges to the store of access tokens for larger research organisations, So that they can make use of Access token in future to present them to ORCID to interact with their researchers’ ORCID profiles

[ORCIDHUB-18] created by rpaw053
@rpaw053
Copy link
Member Author

rpaw053 commented Jan 24, 2017

The privileges can be managed through DB constraints and through Code, Simple API can be written if needed.

by rpaw053

@rpaw053
Copy link
Member Author

rpaw053 commented Feb 13, 2017

If that "make use of Access token in future" has an implicit "through the ORCID Hub" then totally. If it's download a copy of my researchers tokens for my other integration, then would disagree as I'm not sure it's desirable for RO Admins to be able to interact directly with tokens.
Remember each Member has 5 sets of credentials, so rather then increasing the attack surface of the token store, we could sensibly recommend/insist that orgs wanting tokens for their own integrations get direct permission. This would make privacy sense too.

by jgus614

@rpaw053
Copy link
Member Author

rpaw053 commented Mar 30, 2017

Hmmn, I'm reminded that Govt Org's under one of the open govt or data frameworks would need this facility.

Should the hub ever shut down (forbid), there has to be a mechanism for the Orgs to get their access tokens out.

by jgus614

@rpaw053
Copy link
Member Author

rpaw053 commented Feb 13, 2018

Edited task to make clear that the access is given by the Hub Admin, and this is resolved.

GH-31 describes the store, the "Can Use Api" flag enforced privilege

by jgus614

@rpaw053 rpaw053 closed this as completed Feb 13, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant