obiba / opal

OBiBa’s core database application for biobanks or epidemiological studies.
http://www.obiba.org/pages/products/opal/
GNU General Public License v3.0
29 stars 22 forks source link

Default permissions on project folders in file system often result in accidental data availability #3781

Open tombisho opened 1 year ago

tombisho commented 1 year ago

Background On many of the projects I work on, the data manager uploads their data files to the project folder in the Opal file system (even if the instructions say not to do this). I think when they click "Import" the default location is the project folder? A standard user that has limited access to the project (e.g. view summaries and edit dictionary) then has access to the raw data files in the project folder. If I then have to explain this to them, it does not give them confidence that the data are secure.

Solution Perhaps only a user with administrate rights on a project should have access to the project folder? Or at least the default folder when the Import button is clicked is to the user (likely administrator) folder?

github-actions[bot] commented 1 week ago

This issue is stale because it has been open for a year with no activity. It will be closed if no further activity occurs. Thank you for your contributions.