Skip to content

Update security/README.md with CLM layer and new scenarios #47

@michaellwest

Description

@michaellwest

Context

The security overview page needs to reference the new CLM features and link to the new documentation pages (#1426 in Console repo).

Changes Needed

Security Layers Diagram

Add CLM as layer 4.5 (between SPE Security Hardening and Logging):

4. SPE Security Hardening
   - Session Elevation (UAC)
   - Web service controls
   - File upload restrictions
   - Delegated access controls
   - Restriction Profiles (CLM)     <-- NEW
   - Remoting API Keys              <-- NEW
   - Trusted Script Registry        <-- NEW
   - Item Path Restrictions         <-- NEW
5. Logging and Monitoring

New Scenario

Add "Scenario 5: Securing Remoting with Restriction Profiles":

  1. Choose a restriction profile (read-only, read-only-strict, content-editor)
  2. Configure profile on remoting service
  3. Optionally create API Keys for per-consumer profiles
  4. Enable audit mode first for dry-run validation
  5. Switch to enforce mode after validating audit logs
  6. Configure item path restrictions for sensitive content

Quick Start Section

Add CLM to the quick start flow after Web Services.

Documentation Navigation

Add links to new pages:

Core Security Topics

Add entries for the new pages under the existing topic list.

Related

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions