Question about restricted files accessible via anonymous private URLs

31 views
Skip to first unread message

Tutasi

unread,
Oct 13, 2025, 3:15:12 AM (4 days ago) Oct 13
to Dataverse Users Community

Hello everyone,

We have a question regarding the behavior of anonymous private URLs in Dataverse.

When an anonymous private URL is generated for a dataset, we noticed that restricted files can still be downloaded through this link, even though the file restriction is correctly applied. Accessing the dataset via the anonymous private URL (from a browser where the user is not logged in) prevents the file from being viewed directly, but still allows it to be downloaded and opened locally.

Is this the expected behavior in Dataverse core?
If so, are there any plans to change it so that restricted files remain fully inaccessible (not downloadable) through anonymous private URLs?

For now, it seems that the only workaround is to avoid including sensitive or identifying information in restricted files (e.g., Readme files) when using anonymous private links.

Thank you in advance for your insights and clarification.

Best regards,

Philip Durbin

unread,
Oct 14, 2025, 9:34:10 AM (2 days ago) Oct 14
to dataverse...@googlegroups.com

"Creating a Preview URL for a draft version of your dataset allows you to share your dataset (for viewing and downloading of files)"

... but it should probably say "including restricted files" because, yes, that's the expected behavior. I just made a pull request to add this: https://github.com/IQSS/dataverse/pull/11897

In the code* there's this comment:

 * The Preview (formerly Private) URL feature has been implemented as a specialized role assignment
 * with an associated token that permits read-only access to the metadata and
 * all files (regardless of if the files are restricted or not) of a draft
 * version of a dataset.

I hope this helps!

Phil


--
You received this message because you are subscribed to the Google Groups "Dataverse Users Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-commu...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/dataverse-community/63db16ea-8ad6-408b-b262-67a5a21fed38n%40googlegroups.com.


--

Philip Durbin

unread,
10:22 AM (5 hours ago) 10:22 AM
to dataverse...@googlegroups.com
For the record, embargoed files can also be downloaded from a Preview URL. I just updated the pull request above, which can be previewed at https://dataverse-guide--11897.org.readthedocs.build/en/11897/user/dataset-management.html#preview-url-to-review-unpublished-dataset
Reply all
Reply to author
Forward
0 new messages