ORNL / DataFed

A Federated Scientific Data Management System
https://ornl.github.io/DataFed/
Other
18 stars 14 forks source link

Private annotation comments visible to other users #650

Open dvstans opened 3 years ago

dvstans commented 3 years ago

See incident report from SynAck - apparently API allows access to data that it shouldn't? This might simply be a misunderstanding of how annotations work.

dvstans commented 3 years ago

While I disagree that this is a security issue, it does highlight some bad behavior. Annotation discussions while open should be restricted to only relevant parties - no one should be able to see the annotation or any related comments. Once activated, anyone can see the annotation, but they still should not see the original discussion unless the owner wants to include it. Once active, no one should be able to add new comments. The owner should be able to edit though.

dvstans commented 3 years ago

The reported issue was already fixed; however, comments above are still valid

JoshuaSBrown commented 1 year ago

Opinion

Again, I think the annotation feature needs a redesign.

dvstans commented 1 year ago

Could you open a new issue with your ideas for a new annotation design - I think this issue should be closed.