Hello,

My name is Ajay Medury, and I am student taking Prof. Germonprez’s class on 
Open Source Tool Development. My team and I have been working on getting the 
SPDX Dashboard up and running and have run into some issues when considering 
the online verification (signing) of SPDX documents. 


We were hoping to get the community’s help on this matter as we have discussed 
three possible alternatives on solving this issue. They are listed below:


Allowing anyone to signoff (verify) an SPDX document after they enter and 
confirm their identity (via a conformation email sent to them) in the form of 
email ids. Then keep track of all verifications in a sort of log, which would 
be recorded in our common database (can answer questions about this if needed).


Allow only a preselected group of users to signoff on documents after they 
first provide and confirm (same as above) their email id, which the system will 
then check to see if this is present in the list of preselected individuals. 
All of these signoffs will also be recorded in the database.


Have a simple login system which has a list of email ids and passwords stored 
in the common database, and allows users to login t signoff on documents. All 
interactions here, including the login and signoff will be logged.



My team and I greatly the community’s input on this matter and look forward to 
hearing from you.


Thank you,

Ajay B. Medury (& Team Dashboard)
_______________________________________________
Spdx-tech mailing list
[email protected]
https://lists.spdx.org/mailman/listinfo/spdx-tech

Reply via email to