Skip to Main Content
Spotfire Ideas Portal
Status Future Consideration
Product Spotfire
Categories Library
Created by Guest
Created on Jul 27, 2016
Merged idea
This idea has been merged into another idea. To comment or vote on this idea, please visit SPF-I-4905 Finer grained security in Spotfire Client.

Permissions and overlapping license rights creates access exploit Merged

We have discovered with our users that our current configuration and understanding of Spotfire License and Permission may not be sufficient for access control.  Please see the following scenario, and confirm if this is true.  If it is, we want to know what can be done to remedy this:
In Short, Spotfire access is divided into two components: Licenses (what rights do you have to use Spotfire) and Permission (what can you do on the folders).  The Licenses precedes the permissions, and it creates the following scenario.

 

  • TWO Teams on a server, Team A and Team B
  • Each team has two groups of users: Power Users (People with the Spotfire Professional + Web License) and Web Users (Web License only)
  • Team A has Folder A; Team B has Folder B
  • Power users have access to write to their own folder Only
  • All users have read access (web access) to each other's folders

In this scenario, the issue is that the Team B Power Users can now open the Team A Report (through Professional License, as their license allows them to do so), remove/edit any filtering and scripting, and peak into the data and other underpinnings of the reports.  The safety of Permissions only ensures that this group of users cannot save into the Team A's Folder.

 ======== 

If this is true, then we believe in this scenario, the problem is that since the license trumps the permission, there is no way for us to control users who have license ability that overrides the folder permissions.

  • Guest
    Reply
    |
    Jul 29, 2016

    I think this boils down to having a permission that lets an analysis file only be opened in the Web Player, even if the user has the "Analyst" licence (since having "Analyst" license plus "Access" permissions to a dxp allows a user to open report in the Analyst and see the underlying report structure and perhaps other data).