[Security] Add explicit managed-file share revocation and expiry #37

Open
opened 2026-07-21 16:48:03 +02:00 by zemion · 0 comments
Owner

Outcome

File owners and authorized administrators can list, revoke, and optionally expire managed-file shares without deleting the underlying file or relying on a replacement grant.

Acceptance

  • List effective direct shares with subject type/id, permission, creator, creation time, and expiry where configured.
  • Revoke one share idempotently through API and central UI actions; repeated revocation is a no-op.
  • Expired/revoked shares stop granting access immediately while owner/tenant policy and other independent grants continue to apply.
  • Grant, change, expiry, and revocation are audited without file content or unrelated recipient data.
  • Tenant, owner, group, and Campaign reference behavior have regression tests.
  • The UI uses Core DataGrid and the standard icon-only table action group.
## Outcome File owners and authorized administrators can list, revoke, and optionally expire managed-file shares without deleting the underlying file or relying on a replacement grant. ## Acceptance - List effective direct shares with subject type/id, permission, creator, creation time, and expiry where configured. - Revoke one share idempotently through API and central UI actions; repeated revocation is a no-op. - Expired/revoked shares stop granting access immediately while owner/tenant policy and other independent grants continue to apply. - Grant, change, expiry, and revocation are audited without file content or unrelated recipient data. - Tenant, owner, group, and Campaign reference behavior have regression tests. - The UI uses Core DataGrid and the standard icon-only table action group.
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: GovOPlaN/govoplan-files#37
No description provided.