indy-node icon indicating copy to clipboard operation
indy-node copied to clipboard

Determine ACLs on who is allowed to request, receive and store additional metrics for `validator-info`

Open WadeBarnes opened this issue 4 years ago • 3 comments

WadeBarnes avatar Mar 21 '21 15:03 WadeBarnes

@lohanspies, Who is best equipped to start this investigation, and where is the relevant resource material?

WadeBarnes avatar Mar 24 '21 14:03 WadeBarnes

@WadeBarnes, here is the Sovrin technical policy document - https://sovrin.org/wp-content/uploads/Steward-Technical-and-Organizational-Policies-V2.pdf

What do you foresee as being part of the initial investigation?

lohanspies avatar Mar 24 '21 17:03 lohanspies

  1. Find/Create an ACL matrix defining what ledger roles have the authority to call the get-validator-info transaction, and indicate what, if any data is filtered out for the given roles. As indicated here, https://github.com/hyperledger/indy-node/issues/1669#issue-837084055, there are differences between the results of the local (on the node) call to validator-info and the remote call to get-validator-info.
  2. Determine which roles should have authority to collect the new data elements.
  3. Update the matrix accordingly.
  4. Implement data filtering on get-validator-info as needed based on the updated matrix.

WadeBarnes avatar Mar 24 '21 19:03 WadeBarnes