globaleaks / GlobaLeaks

GlobaLeaks is free, open-source software enabling anyone to easily set up and maintain a secure whistleblowing platform.
https://www.globaleaks.org
Other
1.21k stars 267 forks source link

document the custodian user role #3810

Open mapreri opened 9 months ago

mapreri commented 9 months ago

What version of GlobaLeaks are you using?

4.13.18

What browser(s) are you seeing the problem on?

Other

What operating system(s) are you seeing the problem on?

Linux

Describe the issue

The current documentation, as live in https://docs.globaleaks.org/en/main/ - does not seem to ducument what is a custodian user and in which case it might make sense to have one.

Proposed solution

No response

evilaliv3 commented 9 months ago

Thank you @mapreri

The custodian user role is a feature built for the Italian national authority for anticorruption that as community we do not endorse so much and this is why it is not directly exposed and not so much documented.

A custodian is a user which role is to read motivated requests by recipients to access the identity of a whistleblower and that are enable to grant this authorization.

The feature makes some sense but is impractical an risky for many reasons:

What do you think?

mapreri commented 9 months ago

A custodian is a user which role is to read motivated requests by recipients to access the identity of a whistleblower and that are enable to grant this authorization.

this sounds... totally against the whole principle of this software.....

I see now why you are not exposing the feature, which makes sense, however please consider still documenting it: what you wrote in this issue is already a great starting point, just add a visible warning against using this feature.