Skip to content

Cui 2026: update how CUI/access permissions are handled.. and some bug fixes - #239

Open
RobLBaker wants to merge 43 commits into
mainfrom
cui_2026
Open

RobLBaker wants to merge 43 commits into
mainfrom
cui_2026

Conversation

@RobLBaker

Copy link
Copy Markdown
Member

This is a bit of a larger and more sprawling pull request. The main body consists of updating how CUI are handled to better correspond with upcoming DataStore changes in release 4.4 (scheduled October 2026).

  1. The access elements now contain general information about permissions. These are not used by DataStore but are intended to give users a quick way to assess permissions.

  2. Permissions are actually held in additionalMetadata and give a lot more specific information now than just "PUBLIC" vs. "RESTRICTED"

  3. There are several bug fixes to other functions, primarily when the force parameter is set to TRUE. It seems this little-used option was not thoroughly tested previously.

  4. updated unit tests.

…_marking and start finction set_legal_authority.
fix bug in set_permissions when force = TRUE
@aserrantes
aserrantes self-requested a review October 1, 2026 20:22
<div class="ref-description section level2">
<p><code>set_cui_code()</code> adds Controlled Unclassified Information (CUI) dissemination codes to EML metadata. These codes determine who can or cannot have access to the data. Unless you have a specific mandate to restrict data, all data should be available to the public. if the CUI dissemination code is PUBLIC, the CUI marking should also be PUBLIC (<code>see set_cui_marking()</code>) and the license should be set to CC0 or public domain (see <code><a href="set_int_rights.html">set_int_rights()</a></code>). If your data contains CUI and you need to set the CUI dissemination code to anything other than PUBLIC, please be prepared to provide a legal justification in the form of the appropriate CUI marking (see <code><a href="set_cui_marking.html">set_cui_marking()</a></code>).</p>
<p><a href="https://lifecycle.r-lib.org/articles/stages.html#deprecated" class="external-link"><img src="figures/lifecycle-deprecated.svg" alt="[Deprecated]"></a>
<code>set_cui_code()</code> adds Controlled Unclassified Information (CUI) dissemination codes to EML metadata. These codes determine who can or cannot have access to the data. Unless you have a specific mandate to restrict data, all data should be available to the public. if the CUI dissemination code is PUBLIC, the CUI marking should also be PUBLIC (<code>see set_cui_marking()</code>) and the license should be set to CC0 or public domain (see <code><a href="set_int_rights.html">set_int_rights()</a></code>). If your data contains CUI and you need to set the CUI dissemination code to anything other than PUBLIC, please be prepared to provide a legal justification in the form of the appropriate CUI marking (see <code><a href="set_cui_marking.html">set_cui_marking()</a></code>).</p>

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
<code>set_cui_code()</code> adds Controlled Unclassified Information (CUI) dissemination codes to EML metadata. These codes determine who can or cannot have access to the data. Unless you have a specific mandate to restrict data, all data should be available to the public. if the CUI dissemination code is PUBLIC, the CUI marking should also be PUBLIC (<code>see set_cui_marking()</code>) and the license should be set to CC0 or public domain (see <code><a href="set_int_rights.html">set_int_rights()</a></code>). If your data contains CUI and you need to set the CUI dissemination code to anything other than PUBLIC, please be prepared to provide a legal justification in the form of the appropriate CUI marking (see <code><a href="set_cui_marking.html">set_cui_marking()</a></code>).</p>
<code>set_cui_code()</code> adds Controlled Unclassified Information (CUI) dissemination codes to EML metadata. These codes determine who can or cannot have access to the data. Unless you have a specific mandate to restrict data, all data should be available to the public. If the CUI dissemination code is PUBLIC, the CUI marking should also be PUBLIC (<code>see set_cui_marking()</code>) and the license should be set to CC0 or public domain (see <code><a href="set_int_rights.html">set_int_rights()</a></code>). If your data contains CUI and you need to set the CUI dissemination code to anything other than PUBLIC, please be prepared to provide a legal justification in the form of the appropriate CUI marking (see <code><a href="set_cui_marking.html">set_cui_marking()</a></code>).</p>

Comment thread R/editEMLfunctions.R
#'
#' @description `r lifecycle::badge("experimental")`
#' `r lifecycle::badge("deprecated")`
#' The Controlled Unclassified Information (CUI) marking is different from the CUI dissemination code. The CUI dissemination code (set `set_cui_code()`) sets who can have access to the data package. The CUI marking set by `set_cui_marking()` specifies the reason (if any) that the data are being restricted.

@aserrantes aserrantes Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should set_cui_code() here be updated to set_permissions()?


If you choose INTERNAL or RESTRICTED you must also supply a contact email address for people who want to request access (we suggest a group email rather than in individual person's email due to frequent personnel turnover) and a specific person's name who is responsible for making the decision to restrict the file downloads.

```{r dessemination permissions, eval = FALSE}

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why is eval set to FALSE?

@aserrantes aserrantes left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left a few comments, nothing critical. Looks good, works as intended and creates schema valid metadata objects. Setting force = TRUE for both set_permissions and set_int_rights works as well.
Friendly reminder to update DPchecker! The new permissions cause checks to fail in its current form.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants