atomic-server
atomic-server copied to clipboard
Dealing with public, but not searchable, Invites
Docs discussion https://github.com/ontola/atomic-data-docs/issues/88
Although Invites should be public (you must open them as a guest), they should not appear in public indexes, such as Collections or Search results. They are tokens whose identity (URL) should be a secret to normal people.
How to deal with this?
Do not have a read on Invites, but some other right (e.g. readOnOpen)
Seems reasonable, but introduces a new grant type, which can be complicated.
Hard-code skipping invites in collecttions / search
... yuck