keybase / keybase/client

Suggestion for change to KBFS

Open
#10,527 6 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
9.2k
Forks
1.3k
PR merge metrics
PR metrics pending

Description

Hi,
I would like to suggest a change that may be a bit deeper in the KBFS.
I am in a group where we deal with files that can contain sensitive information (especially video's) that we would like to protect from distributing freely.
We can set a person to be a reader and they will have access only to read the files, that is great. However they are also able to copy the file to other locations, also outside of the file system.
We would like to see an option where we can prevent files from leaving the folder to other destinations other then a sandbox where they can temporary be stored for viewing (not relocated).
It would be sufficient if this can be set alone for readers for a whole folder or even if that would make it easier for readers for a whole team. With sub-teams that could be organized for the the kind of information that we are dealing with.
For others it might even better if the owner of file (for writers) or admin could copy the file but not other writers. I guess also in here on folder level would be sufficient.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading KBFS's existing reader, writer, and admin permission model, including how folder-level access is enforced. The issue needs a settled design for copying files, temporary viewing storage, sandbox boundaries, and team or folder scope before implementation can be considered done.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.