You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I would like to start by congratulating and thanking the entire team for developing GeoLens. I have been studying and testing the platform for a week, exploring both the Web GUI and the APIs. I am very excited about running a pilot project with this platform at my workplace (I work at a specialized wildfire management center in the Brazilian government).
Context
During my data and user administration tests — specifically when populating the environment via scripts/seed-showcase.py and attempting vector feature editing in GIS software (QGIS) using the GeoLens Plugin and OGC/WFS connections —, I encountered a few scenarios regarding the permission model and dataset ownership management.
1. Multi-user write permissions for Datasets
I tested feature editing in QGIS via the GeoLens Plugin. The workflow worked seamlessly when authenticated as an Admin. However, when attempting the exact same feature editing as a user with the Editor role (who is not the original dataset owner), the operation was blocked. Additionally, connecting via the OGC/WFS provider appears to be strictly read-only by design.
Question: Is this ownership-restricted editing behavior expected within the current security model?
Use Case: In operational workflows, we have field teams and GIS analysts who need to edit geometric features on the exact same layer concurrently, while other roles should only have read-only access. Granting the Admin role to the entire operational team violates the principle of least privilege. Is there any plan on the roadmap to support ACLs (Access Control Lists) or delegated editing roles per dataset/collection?
2. Changing and Displaying Dataset Ownership
Since the environment was seeded via the administrative script, all datasets were assigned to the admin account.
Question: What is the recommended REST API procedure to transfer the ownership of an existing dataset to another user who holds an Editor role profile?
UX/UI Suggestion: In the Web GUI, I couldn't find the current Owner displayed under the dataset details, nor an option to manage/transfer ownership. For catalog governance, it would be extremely helpful to show the dataset owner in the UI and allow administrators to perform ownership transfers directly from the interface.
Thank you very much in advance for your time and support!
What I've tried
Configured local environment via Docker Compose and seeded demo datasets using scripts/seed-showcase.py.
Created separate user accounts with different roles (Admin and Editor).
Tested vector layer feature editing in QGIS using the GeoLens Plugin and OGC/WFS provider with API Keys/credentials from both roles.
Confirmed that feature editing succeeds for Admin users via the GeoLens Plugin, but non-owner Editor users are blocked from saving edits by the plugin.
Confirmed that OGC/WFS connections function strictly as read-only layers.
Searched the official API documentation for endpoints or parameters to transfer or update dataset ownership, but could not find a supported method.
Inspected the Web GUI dataset details panel and settings to identify options for dataset ownership management or ownership display.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Question
Acknowledgments
I would like to start by congratulating and thanking the entire team for developing GeoLens. I have been studying and testing the platform for a week, exploring both the Web GUI and the APIs. I am very excited about running a pilot project with this platform at my workplace (I work at a specialized wildfire management center in the Brazilian government).
Context
During my data and user administration tests — specifically when populating the environment via
scripts/seed-showcase.pyand attempting vector feature editing in GIS software (QGIS) using the GeoLens Plugin and OGC/WFS connections —, I encountered a few scenarios regarding the permission model and dataset ownership management.1. Multi-user write permissions for Datasets
I tested feature editing in QGIS via the GeoLens Plugin. The workflow worked seamlessly when authenticated as an Admin. However, when attempting the exact same feature editing as a user with the Editor role (who is not the original dataset owner), the operation was blocked. Additionally, connecting via the OGC/WFS provider appears to be strictly read-only by design.
Adminrole to the entire operational team violates the principle of least privilege. Is there any plan on the roadmap to support ACLs (Access Control Lists) or delegated editing roles per dataset/collection?2. Changing and Displaying Dataset Ownership
Since the environment was seeded via the administrative script, all datasets were assigned to the
adminaccount.Thank you very much in advance for your time and support!
What I've tried
scripts/seed-showcase.py.AdminandEditor).Adminusers via the GeoLens Plugin, but non-ownerEditorusers are blocked from saving edits by the plugin.GeoLens version
v1.20.0 - Build: f5fee67
Deployment method
Docker Compose
All reactions