[ 
https://jira.duraspace.org/browse/DS-426?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Claudia Jürgen updated DS-426:
------------------------------

    Attachment: DS-426.patch

This patch prevents unauthorized access of the items submission license by 
using retrieval links like

http://localhost:8080/dspaceTrunk/retrieve/[ID]/license.txt
http://localhost:8080/dspaceTrunk/retrieve/[ID]

for instances where the licenses are supposed to not be displayed i.e. where
the configuration parameter

webui.licence_bundle.show is set to false.






> Item's submission license accessible without beiing configured to be public
> ---------------------------------------------------------------------------
>
>                 Key: DS-426
>                 URL: https://jira.duraspace.org/browse/DS-426
>             Project: DSpace
>          Issue Type: Bug
>          Components: JSPUI
>    Affects Versions: 1.6.0
>            Reporter: Claudia Jürgen
>            Priority: Major
>         Attachments: DS-426.patch
>
>
> The item's license derives it's rights during the submission process from the 
> default settings of the collection.
> So on a collection with default item read set to anonymous the READ for the 
> license.txt is set to anonymous.
> Per default the license is not shown in the item page, as it contains 
> information which might conflict with privacy laws. Furthermore it is of 
> little use for the end user, because it usually does not contain the terms of 
> use.
> In the JSPUI it is possible to retrieve the license via the direct retrieve 
> link regardless of the configuration settings.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: 
https://jira.duraspace.org/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

       

------------------------------------------------------------------------------
Nokia and AT&T present the 2010 Calling All Innovators-North America contest
Create new apps & games for the Nokia N8 for consumers in  U.S. and Canada
$10 million total in prizes - $4M cash, 500 devices, nearly $6M in marketing
Develop with Nokia Qt SDK, Web Runtime, or Java and Publish to Ovi Store 
http://p.sf.net/sfu/nokia-dev2dev
_______________________________________________
Dspace-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/dspace-devel

Reply via email to