Sharing content that requires HarvardKey protection

About HarvardKey protection and file storage

Many sites need to share information with a limited audience, such as HR records, financial documents, committee materials, or draft reports. HarvardSites Drupal lets you restrict an entire site behind HarvardKey login. This works well for page content.

It does not work the same way for uploaded files.

There is no way to HarvardKey-protect an individual file in HarvardSites Drupal. A PDF, Word document, spreadsheet, or image uploaded to the Drupal file system is stored and served the same way regardless of whether the page it's linked from is public or HarvardKey-protected. If someone has, guesses, or shares the direct file URL, they can potentially open it without logging in, even on a HarvardKey-protected site.

For this reason, HWP recommends storing any file containing sensitive or restricted information in Harvard SharePoint and linking to it from your Drupal site, rather than uploading the file directly.

Important: Page protection is not file protection

Restricting a site behind HarvardKey controls who can view that site. It does not extend to files attached to or embedded on that site or page.

Do not rely on a HarvardKey-protected site to safeguard uploaded files. If a file contains anything beyond low-risk, publicly shareable information, don't upload it to HarvardSites Drupal at all. Store it in SharePoint, where access can be controlled at the file or folder level, and link to it instead.

Deciding where content belongs

Before you decide how to share something, classify it. Harvard's risk classification standard defines five levels based on the impact of exposure. Use the "high watermark" rule: if any part of the content is more sensitive than the rest, classify the whole file at that higher level. If you're unsure how to classify something, reach out to your school's Information Security Officer, or contact the ISDP team before publishing it anywhere.

How to share a SharePoint file from your Drupal site

  1. Upload the file to a Harvard SharePoint site or folder with permissions limited to the appropriate audience (a specific group, a school, or "People in Harvard University with the link," as appropriate for the content's risk level).
  2. In SharePoint, generate a sharing link scoped to that same restricted audience. Avoid "Anyone with the link" for anything above Level 1.
  3. In HarvardSites Drupal, add a text link, button, or call-to-action component and point it to the SharePoint URL rather than uploading the file to Drupal.
  4. Log out of HarvardKey (or use a private browser window) and test the link to confirm it prompts for HarvardKey sign-in and that access is limited as expected.
  5. Revisit permissions periodically, especially when staff turnover or committee membership changes, since Drupal has no way to reflect SharePoint permission changes automatically.

Reviewing the risk level of existing files

If your site already has files uploaded directly to Drupal that contain Level 2 or higher information, move them to SharePoint and update the links. Don't assume that placing a page behind HarvardKey after the fact retroactively protects files that are already linked from it.