Back to OSGeo (Open Source Geospatial Foundation)
GSoC 2026

istSOS Role-Based Web Administration

This project adds proper role-based access control to istSOS4 by making the web administration interface reflect the permissions already enforced in PostgreSQL through Row-Level Security (RLS). Right now, the backend enforces access correctly, but the UI does not — every user sees the same controls. This project fixes that. Each role (administrator, editor, viewer, sensor) will only see the pages and actions they are allowed to use. It also simplifies user and policy management by removing the current two-step workflow. Creating or updating a user will automatically apply the appropriate policies, reducing configuration mistakes and making the system easier to operate. To support real deployments, the project adds basic observability and debugging tools. A permission matrix shows what each role can do, and audit logs record access-related events. In addition, small utilities like permission explanation, access simulation, and change impact preview help admins understand and verify changes before applying them. The project also explores integration with external authentication providers (OIDC) so istSOS4 can work with single sign-on setups, including Grafana, without changing how permissions are enforced. Overall, the focus is to make permissions visible, predictable, and manageable for administrators.

Project details

Contributor

Kinshuk Sanand

Mentors

Not available

Technologies

Not listed in the archive