hypothesis / hypothesis/product-backlog

Require ORICD for group membership

Open
#845 1 comment 1 reaction 0 assignees View on GitHub
groups user requested
Dominant language
No language data
Stars
122
Forks
7
PR merge metrics
No merged PRs in 30d

Description

### User story:
As a publisher I want to require that all users of Hypothesis have their ability to write annotations in a group restricted by their ORCID authentication, so that I can control who can create annotations on my site.

NOTE: Your user account has to be authenticated against ORCID in order for you to annotate in this group. It is a one time authorization model.

Acceptance criteria:
- Groups can require that users must be authenticated into ORCID to annotate in the group.
- For users in a group who have not authenticated against ORCID, annotation interface indicates that this is required and provides a link to do so.
- From their profile, users can connect to ORCID, and once connected, can see that status reflected (in their profile, etc).
- The existing ORCID number field in the user profile will then be populated by this authentication vs by the user typing it in directly. (What do we do about existing ORCID values?)
- A small ORCID icon shows next to the username throughout the interface*.

Q: Can users decouple the authentication later? Or change it?

*Not a necessary requirement
Partners waiting on this:
bioRxiv
ESSOAr
Wiley

Create a mechanism for us to verify someone has an ORCID account
Create a group configuration that requires ORCID as a trust provider

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the acceptance criteria and the open questions about ORCID connection, existing ORCID values, and decoupling. Identify the product and implementation entry points for group trust-provider configuration, profile authentication, annotation access, and interface status; done means the listed ORCID restrictions and connection flows are implemented and verified.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, authorization
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.