diff --git a/config/galaxy.ini.sample b/config/galaxy.ini.sample index cf97086f132..c9e32f42bc8 100644 --- a/config/galaxy.ini.sample +++ b/config/galaxy.ini.sample @@ -1110,9 +1110,14 @@ use_interactive = True #enable_quotas = False # This option allows users to see the full path of datasets via the "View -# Details" option in the history. Administrators can always see this. +# Details" option in the history. This option also exposes the command line to +# non-administrative users. Administrators can always see dataset paths. #expose_dataset_path = False +# This option allows users to see the job metrics (except for environment +# variables). +#expose_potentially_sensitive_job_metrics = False + # Data manager configuration options # Allow non-admin users to view available Data Manager options. #enable_data_manager_user_view = False diff --git a/lib/galaxy/config.py b/lib/galaxy/config.py index 2e7d391f925..2e7caaf741f 100644 --- a/lib/galaxy/config.py +++ b/lib/galaxy/config.py @@ -217,6 +217,7 @@ class Configuration( object ): self.track_jobs_in_database = string_as_bool( kwargs.get( 'track_jobs_in_database', 'True') ) self.start_job_runners = listify(kwargs.get( 'start_job_runners', '' )) self.expose_dataset_path = string_as_bool( kwargs.get( 'expose_dataset_path', 'False' ) ) + self.expose_potentially_sensitive_job_metrics = string_as_bool( kwargs.get( 'expose_potentially_sensitive_job_metrics', 'False' ) ) self.enable_communication_server = string_as_bool( kwargs.get( 'enable_communication_server', 'False' ) ) self.communication_server_host = kwargs.get( 'communication_server_host', 'http://localhost' ) self.communication_server_port = int( kwargs.get( 'communication_server_port', '7070' ) ) diff --git a/templates/show_params.mako b/templates/show_params.mako index a18a73895c5..dde5ea3cad9 100644 --- a/templates/show_params.mako +++ b/templates/show_params.mako @@ -230,17 +230,18 @@ -%if job and job.command_line and trans.user_is_admin(): +%if job and job.command_line and (trans.user_is_admin() or trans.app.config.expose_dataset_path):
${ job.command_line | h }
%endif
-%if job and trans.user_is_admin():
+%if job and (trans.user_is_admin() or trans.app.config.expose_potentially_sensitive_job_metrics):