ckan / ckan/ideas

Anonymize publisher users

Open
#105 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
39
Forks
1
PR merge metrics
No merged PRs in 30d

Description

User accounts are public on CKAN, yet when CKAN is used by governments these are civil servants who should not be disclosed.

e.g. look at an activity stream and it says who created it - even the username could have a personal name in and that should not be public. Also, you should not be able to click on the user to see what else they have done. And you should not be able to see a list of all users at /user.

The original premise behind making user accounts public, was that CKAN was a social network, like github. However I think government administrators just doing their job should not be identified by default. Showing people's names doesn't seem right e.g.: http://data.glasgow.gov.uk/organisation/activity/british-transport-police

So I propose that anyone with an admin or editor role should be shown publicly as "Admin for Cabinet Office" or something. And if you have a role with Cabinet Office then you can actually see the exactly who it was. If there are sites that genuinely want to make admin/editors public then maybe we need a config option to do this?

This is basically what data.gov.uk has implemented in its templates and hacks to CKAN core. data.gov doesn't have users because it harvests. I believe Canada ends up stripping out users in its harvest.

Contributor guide

No contributing guide indexed for this repository

Research direction

Review the proposed behavior for activity streams, user profiles, and the /user listing, along with the mention of data.gov.uk templates and CKAN core hacks. First determine whether this proposal belongs in the main CKAN repository, as this ideas repository is deprecated. Done would require an agreed privacy model and implementation scope for public identities, role-based visibility, and any configuration option.

Written by the indexing model from the issue text.

Assessment

Domain
authorization, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.