06.14.2021 TT Agenda - QualitativeDataRepository/TechnicalTeam GitHub Wiki

Previous week Updates

  • None

Team Discussion

  • None

Infrastructure updates

  • SO - > Will provide some guidance on VPN users (e.g. how many times should a user be able to login over a period of time)
  • SO -> Will look for Shiboleth pen testing

Development updates

Jim's weekly report

  • User activity logs in Dataverse through guestbook, etc.

To discuss:

Notes

  • IDP user login - Seba has a working prototype for Prod that can enforce actions on user activity...

  • Shibboleth penetration testing...

  • SK is out Thursday until Mid-July

JM

  • Deploying 5.5 was last weeks activity
  • Guestbook on DV (doesn't show up in UI) - but this is logging all user activity in the background. This allows us to understsand what actions a user is taking (e.g. delete or filter users - as well as understanding role assignments, files uploaded, files downloaded etc)
  • JM updated the API so that we could request info on what activities a user took w/r/t data access
    • Right now we're not getting the dataset version for user activity - this may be important in the future for parsing exactly what a user accessed / downloaded...
  • Use case driving -> security of who downloaded what etc ...
  • Traces API - delete vs deactivated ... once a user has downloaded a dataset they can't be deleted - so the deactivated is the work around

Assigned Tasks