From f2aad3416e6441761d30e21b9e1f328743f7fe41 Mon Sep 17 00:00:00 2001 From: Alok Saldanha Date: Sun, 14 Nov 2021 13:59:07 -0500 Subject: [PATCH] added idea for authorization --- Data-based-Authorization.md | 14 ++++++++++++++ 1 file changed, 14 insertions(+) create mode 100644 Data-based-Authorization.md diff --git a/Data-based-Authorization.md b/Data-based-Authorization.md new file mode 100644 index 0000000..389e64e --- /dev/null +++ b/Data-based-Authorization.md @@ -0,0 +1,14 @@ +In some settings, it may be desirable to restrict access to particular datasets to particular individuals. The identity of users is typically passed via HTTP request headers such as the Cookie or Authorization headers. We expect that the precise mechanism will vary greatly. In order to support this with maximum flexibility, we propose to add a `is_authorized(descriptor): Boolean` method to the ItemSource interface. `is_authorized` will be called prior to `CacheEntry.serve_content` to verify that the user is allowed to access the indicated path. The default implementation for the provided FileItemSource and S3ItemSource always return true; an example implementation that requires that a `meaning-of-life` Cookie containing the text `42` could look as follows: +``` +from flask import request +from cellxgene_gateway.gateway import item_sources, launch + +class AdamsFileItemSource(FileItemSource): + def is_authorized(descriptor: string): + cookie = request.cookies.get('meaning-of-life', '') + return cookie.find('42') != -1 + +cellxgene_data = os.environ.get("CELLXGENE_DATA", None) +item_sources.push(AdamsFileItemSource(cellxgene_data, "adams")) +launch() +``` \ No newline at end of file