atom icon indicating copy to clipboard operation
atom copied to clipboard

Problem: PDF masters can still be accessed by public users even when permissions are configured to deny

Open anvit opened this issue 1 year ago • 0 comments

Current Behavior

From Google Groups

Admin

  • A simple archival description has been created:
    • Fonds > Series > File/Item (digital object import, i.e. document.pdf)
  • Group > anonymous > All archival description:
    • All options are set to deny, except for 'read,' which is granted.
  • All premis act > Disallow permissions
    • Master, Reference and Thumb -> uncheked
  • document.pdf > create new rights > Act/granted rights
    • Discover, display, replicate -> Disallow

Anonymous User

  • Can read the archival description and the pdf is displayed.

Expected Behavior

Anonymous user should not be able to see the pdf.

Possible Solution

No response

Context and Notes

This is a known behaviour in AtoM and PDFs are an exception to PREMIS rules as a sort of a workaround. Dan shared more context on the Google groups thread.

Version used

AtoM 2.7.3

anvit avatar Nov 22 '23 17:11 anvit