xchem / xchem_it

Issues for XChem IT work
0 stars 0 forks source link

ISPYB authorisation in Keycloak #9

Open tdudgeon opened 3 years ago

tdudgeon commented 3 years ago

If information from private Fragalysis projects is sent to Discourse that information would be publicly visible. In order to restrict access we probably need to provide access control information in the Keycloak tokens, which probably means writing a plugin in Keycloak that queries ISPYB to get the necessary information and then adding appropriate roles to the keycloak token.

This needs careful design, possibly outside consultancy.

reskyner commented 3 years ago

This is important, but currently not easy/fast. Needs to be investigated internally by @reskyner