PUI Request modal includes location information

Description

The PUI request modal include the location title (location_title[]) as a hidden field in the request form for an archival object. This is a potential security risk as it exposes physical location information to the public. Suggest this be omitted from the request form modal or allow configuration option to remove.

Environment

Tested in sandbox and locally (mac o/s)

Bug Report Description

None

Activity

Show:

Benn Joseph December 10, 2021 at 8:04 PM

Weird question here: if we actually do want location info to show up in the PUI as it currently does for us in v.2.8.1, is there a way to keep this bug (or feature for us)? I ask because our location info is not configured in such a way that makes it a big security risk, and we are interested in configuring our Aeon integration plugin to pass this location info to requests submitted by researchers using the PUI (currently we can only pass location info to Aeon requests using the Aeon client integration w/ ASpace, and that is staff-use only). Thanks!

Rachel Searcy May 10, 2021 at 2:33 PM

This looks to be fixed in test instance. Location information does not currently display in the request form.

Joshua Shaw May 4, 2021 at 1:54 PM

Appears to be fixed. Location information no longer present in modal.

Mark Cooper April 22, 2021 at 6:29 PM

it looks like the location information is superfluous, particularly considering the potential for sensitive information leaking. The staff request email includes uris for the record and any associated top containers so with that information it’s easy to go to ArchivesSpace and pull the location w/o any location data having to be included in the request form.

Done

Details

Assignee

Reporter

Sprint

Fix versions

Priority

Harvest Time Tracking

Open Harvest Time Tracking

Created February 28, 2019 at 3:22 PM
Updated December 10, 2021 at 8:04 PM
Resolved May 6, 2021 at 9:37 PM
Harvest Time Tracking