Summary | Free/Busy URL privacy |
Queue | Kronolith |
Queue Version | 2.1.1 |
Type | Enhancement |
State | Accepted |
Priority | 1. Low |
Owners | |
Requester | stavros (at) staff (dot) esc (dot) net (dot) au |
Created | 06/16/2006 (6907 days ago) |
Due | |
Updated | 11/16/2008 (6023 days ago) |
Assigned | |
Resolved | |
Milestone | |
Patch | No |
free/busy information there. I think we should go back to the same
thing we used to do of using the VIEW permission for free/busy info.
We can turn it on by default, perhaps as a conf.php setting.
Also, we could learn a few things about the calendar/share management
interface from google calendar. But I suspect we all knew that
already. :)
But the option for users to turn the FB of and configure the Information
shown would work for our site.
to get free/busy info. So the option should be for users to turn off
their free/busy info, or for users to mask their name/email in it?
user, thus they will never see any user name or email in the fb
publish information or in the meeting planning interface.
and what does the requester think of simply omitting name and email
address from the F/B info if the user doesn't have permissions to the
calendar?
dublicated i will repost my sugestion here to keep it on this request.
--------------------
Make free/busy informations shares
Making the free/busy information share has some advantages.
1. It will allow the user to controll who is able to acces the information
2. The user can have more than one F/B url (with different calendars
checked and different permisions)
3. Only users with acces to the share could connect loginid and
Name/email addres.
Even that could be impeded by generating an URL that does not
contain the loginid
If implemeted that way validating LoginIds would be impossible and geting
emailaddresses would be much harder and only possible for users wich
allow read acces to unauthenticated users
Followin is an example:
A professor could tell his students the URL
horde.some.edu/kronolith/fb.php/aefhca56c4 the see the Free/Busy
informations
which will only contain his consultation-hours as free time.
and his staff members get the URL
horde.some.edu/kronolith/fb.php/ab4h3a0815 which will contain the
Free/Busy information for his working time
he has also a third which share which also contains his private events
and is used when he is planing an events with attendees.
It allows to connect userid to Name and email Adress
It allows spammers to veryfy emailadresses by probing the FB urls
I think it would be usefull to allow users to deactivate generating of
the FB information and/or
to use permissoins system to choose who is able to retrieve these informations
State ⇒ Rejected
Priority ⇒ 1. Low
Priority ⇒ 3. High
State ⇒ New
Queue ⇒ Kronolith
Summary ⇒ Free/Busy URL Security Issue
Type ⇒ Enhancement
information is available to anyone who wants it.