DawidPotgieter / Dynamics-CRM-Binary-Storage-Options

A Dynamics CRM plugin to transparently store attachment binaries outside CRM database. Azure Blob or File storage for instance.
GNU Affero General Public License v3.0
34 stars 15 forks source link

Access Question #20

Closed KeithMattMurphy closed 4 years ago

KeithMattMurphy commented 5 years ago

Hi Dawid This looks like a fantastic solution. Maybe a silly question but I'm unsure how the security works with this? Will only the CRM owners of the Note/Email be able to view the attachment once moved to blob storage or can anyone inside / outside the organisation see it?

thanks a million Keith

DawidPotgieter commented 5 years ago

Hi there Keith,

When ou set up your blob storage, you would set that to ‘private’. This means that only someone/systems with your storage key will have access to the files.

You then provide that key to CRM in configuration, which only CRM administrators have rights to.

The plugins do not actually move notes or emails, only the binary part of the attachments.

Thus, in reality, the access is controlled by CRM, and you configure those on a role by role basis. Think of it as the security staying the same as it was, except you’re using different underlying storage.

Hope that answers your question.


From: naas2005 notifications@github.com Sent: Friday, May 3, 2019 1:48:01 AM To: DawidPotgieter/Dynamics-CRM-Binary-Storage-Options Cc: Subscribed Subject: [DawidPotgieter/Dynamics-CRM-Binary-Storage-Options] Access Question (#20)

Hi Dawid This looks like a fantastic solution. Maybe a silly question but I'm unsure how the security works with this? Will only the CRM owners of the Note/Email be able to view the attachment once moved to blob storage or can anyone inside / outside the organisation see it?

thanks a million Keith

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHubhttps://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2FDawidPotgieter%2FDynamics-CRM-Binary-Storage-Options%2Fissues%2F20&data=02%7C01%7C%7C189e52ad8a4649b286d308d6cf04cc1e%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C636924016837709008&sdata=BUukWIAESuOmOHxRLct745%2FY07PRWsOGQBVi1Cd09%2FU%3D&reserved=0, or mute the threadhttps://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fnotifications%2Funsubscribe-auth%2FAE4S3QDSSJ3VC4ZMX3R3U7TPTLWJDANCNFSM4HJ6Q2GA&data=02%7C01%7C%7C189e52ad8a4649b286d308d6cf04cc1e%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C636924016837719013&sdata=%2Futez%2F8CCX%2Bd5os7G9fyXU369uf4kI%2BlS5%2BFy7rm2u0%3D&reserved=0.

KeithMattMurphy commented 5 years ago

Hi David

That's great - thanks very much. Looking forward to testing it out

Regards Keith

On Thu, May 2, 2019 at 8:26 PM Dawid Potgieter notifications@github.com wrote:

Hi there Keith,

When ou set up your blob storage, you would set that to ‘private’. This means that only someone/systems with your storage key will have access to the files.

You then provide that key to CRM in configuration, which only CRM administrators have rights to.

The plugins do not actually move notes or emails, only the binary part of the attachments.

Thus, in reality, the access is controlled by CRM, and you configure those on a role by role basis. Think of it as the security staying the same as it was, except you’re using different underlying storage.

Hope that answers your question.


From: naas2005 notifications@github.com Sent: Friday, May 3, 2019 1:48:01 AM To: DawidPotgieter/Dynamics-CRM-Binary-Storage-Options Cc: Subscribed Subject: [DawidPotgieter/Dynamics-CRM-Binary-Storage-Options] Access Question (#20)

Hi Dawid This looks like a fantastic solution. Maybe a silly question but I'm unsure how the security works with this? Will only the CRM owners of the Note/Email be able to view the attachment once moved to blob storage or can anyone inside / outside the organisation see it?

thanks a million Keith

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub< https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2FDawidPotgieter%2FDynamics-CRM-Binary-Storage-Options%2Fissues%2F20&data=02%7C01%7C%7C189e52ad8a4649b286d308d6cf04cc1e%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C636924016837709008&sdata=BUukWIAESuOmOHxRLct745%2FY07PRWsOGQBVi1Cd09%2FU%3D&reserved=0>, or mute the thread< https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fnotifications%2Funsubscribe-auth%2FAE4S3QDSSJ3VC4ZMX3R3U7TPTLWJDANCNFSM4HJ6Q2GA&data=02%7C01%7C%7C189e52ad8a4649b286d308d6cf04cc1e%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C636924016837719013&sdata=%2Futez%2F8CCX%2Bd5os7G9fyXU369uf4kI%2BlS5%2BFy7rm2u0%3D&reserved=0

.

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub https://github.com/DawidPotgieter/Dynamics-CRM-Binary-Storage-Options/issues/20#issuecomment-488800901, or mute the thread https://github.com/notifications/unsubscribe-auth/ACDQ2NALC3HBTPO22ADD2MDPTM55HANCNFSM4HJ6Q2GA .