Hello,
My name is Ajay Medury, and I am student taking Prof. Germonprez’s class on
Open Source Tool Development. My team and I have been working on getting the
SPDX Dashboard up and running and have run into some issues when considering
the online verification (signing) of SPDX documents.
We were hoping to get the community’s help on this matter as we have discussed
three possible alternatives on solving this issue. They are listed below:
Allowing anyone to signoff (verify) an SPDX document after they enter and
confirm their identity (via a conformation email sent to them) in the form of
email ids. Then keep track of all verifications in a sort of log, which would
be recorded in our common database (can answer questions about this if needed).
Allow only a preselected group of users to signoff on documents after they
first provide and confirm (same as above) their email id, which the system will
then check to see if this is present in the list of preselected individuals.
All of these signoffs will also be recorded in the database.
Have a simple login system which has a list of email ids and passwords stored
in the common database, and allows users to login t signoff on documents. All
interactions here, including the login and signoff will be logged.
My team and I greatly the community’s input on this matter and look forward to
hearing from you.
Thank you,
Ajay B. Medury (& Team Dashboard)
_______________________________________________
Spdx-tech mailing list
[email protected]
https://lists.spdx.org/mailman/listinfo/spdx-tech