# HG changeset patch # User Alain Mazy # Date 1763634398 -3600 # Node ID 3efbbb2f20a73017d88b10e69e4001fa7a964919 # Parent 11d3838f3a269c41b5d5cc8dabfde362af1ae3e7# Parent 79af518c92194d6578df1e641dc192d147fddec7 merge diff -r 79af518c9219 -r 3efbbb2f20a7 NEWS --- a/NEWS Wed Nov 12 13:23:55 2025 +0100 +++ b/NEWS Thu Nov 20 11:26:38 2025 +0100 @@ -3,6 +3,7 @@ * New default permissions for worklists * New default permissions for tools/metrics-prometheus +* New default permissions for tools/generate-uid 2025-10-10 - v 0.10.2 diff -r 79af518c9219 -r 3efbbb2f20a7 Plugin/DefaultConfiguration.json --- a/Plugin/DefaultConfiguration.json Wed Nov 12 13:23:55 2025 +0100 +++ b/Plugin/DefaultConfiguration.json Thu Nov 20 11:26:38 2025 +0100 @@ -60,7 +60,8 @@ // The default configuration is suitable for Orthanc-Explorer-2 (see https://github.com/orthanc-team/orthanc-auth-service) "Permissions" : [ ["post", "^/auth/tokens/decode$", ""], - ["post", "^/tools/lookup$", ""], // currently used to authorize downloads in Stone (to map the StudyInstanceUID into an OrthancID. Not ideal -> we should define a new API that has the resource ID in the path to be able to check it at resource level) but, on another hand, you do not get any Patient information from this route + ["post", "^/tools/lookup$", ""], // currently used to authorize downloads in Stone (to map the StudyInstanceUID into an OrthancID. Not ideal -> we should define a new API that has the resource ID in the path to be able to check it at resource level) but, on another hand, you do not get any Patient information from this route + ["get", "^/tools/generate-uid(.*)$", ""], // used in OE2 when generating worklists but there are no sensitive data to retrieve -> allow all // elemental browsing in OE2 ["post", "^/tools/find$", "all|view"], @@ -142,8 +143,9 @@ ["put", "^/modalities/(.*)$", "admin-permissions"], ["delete", "^/modalities/(.*)$", "admin-permissions"], - // create-delete worklists + // create-edit-delete worklists ["post" , "^/worklists/create$", "all|worklists"], + ["put", "^/worklists/(.*)$", "all|worklists"], ["delete" , "^/worklists/(.*)$", "all|worklists"] ]