innoq / iqvoc

iQvoc - A SKOS(-XL) Vocabulary Management System for the Semantic Web
http://iqvoc.net/
Other
117 stars 44 forks source link

Is there a way to prevent sb from adding Matches data to our instance through Federation feature? #441

Open EwaSniegowskaPCSS opened 1 year ago

EwaSniegowskaPCSS commented 1 year ago

Hi, I really like the Federation option, especially it can prove very useful in our planned setup.

But I'm afraid it can cause security issues. Let's say I have instance iqvoc02 and sb else has instance iqvoc01. If they set our instance URL in their Federation -> Sources option and set Create reverse matches for concept mappings to true, they can add data to our Matches section without our permission or knowledge (I didn't have to provide any credentials to achieve it).

Is this intended behaviour? Can I alter my instance configuration to prevent this?