Browse Workspace assets from QGIS
Private pilot: tested on Mac QGIS 4.2.2 with the configured Keycloak provider. Ask your administrator for the connector installation and HTTPS Workspace address. This is maintained source/pilot packaging, not a public plugin-store release.
Sign in and add a map
Section titled “Sign in and add a map”- In the Ophiolite scalar maps dock, choose Browse Workspace….
- Enter the Workspace server address, then Sign in through browser.
- Check the code and the account shown in the browser, then approve QGIS. Existing browser sign-in may avoid retyping your password; QGIS still receives its own authorization. It does not read browser cookies.
- Set or unlock QGIS’s authentication master password when prompted. This protects the saved connection locally and is separate from your Workspace password.
- Choose a project and scalar map. Review its revision, units, missing values, CRS and vertical reference before adding it.
- Choose Follow latest revision, Pin this exact revision, or Independent local copy, then Add selected asset to QGIS.
An enrolled account and explicit scientific project access are required. Organization membership alone is insufficient. Only conformant scalar maps are currently supported; curves and whole reservoir models are not offered here.
| Choice | What happens after another client publishes |
|---|---|
| Follow | QGIS retrieves and displays the newer revision. |
| Pin | QGIS retains the selected revision, with ongoing access checks. |
| Independent copy | The downloaded raster stays local with no synchronization. |
The raster keeps its source CRS; QGIS transforms its display to your project CRS. The connector does not change the project CRS, scalar units or vertical datum. Unknown coordinates and unavailable transformations require explicit resolution; see coordinate behavior. Local contours and colors are presentation; Rescale live colors does not alter scientific values.
Save and recover
Section titled “Save and recover”Save the normal QGIS project. Its layer bindings contain identity, revision/mode, cache location and an opaque reference to QGIS’s encrypted authentication database. The project contains no access or refresh token. Sharing that project does not share authorization. Downloaded rasters themselves are local files, not encrypted by the credential store.
For another machine, expired sign-in or a different account: sign in again, select the existing connected raster, and choose Reconnect selected QGIS layer with this account. The owning server must match. Reconnect each binding you need. Permissions are checked again on the server. A failed update retains the last snapshot; it does not establish that you still have access.
Disconnect this account revokes the connector authorization and removes its saved credential. It leaves the browser signed in. Downloaded copies remain on disk. If revocation cannot reach the provider, use its account/session settings to revoke access; the local credential is still removed.
Run an operation
Section titled “Run an operation”Select a connected raster and Run server offset…. Review the exact input revision, unit and offset before confirming. The server checks publish/compute permissions and publisher policy. A newer head causes a conflict instead of silently overwriting changes. Following QGIS and View clients update; pins stay fixed. Independent copies cannot submit this shared-asset operation.
Scope and evidence
Section titled “Scope and evidence”Actual Mac QGIS tests covered encrypted credential round-trip, project/asset browsing, follow/pin/local-copy addition, a server offset, preserved project CRS, and saved-project reopening. Real provider/browser tests covered device approval, refresh, denied access and disconnect without browser logout. The tests exercised these pieces together through the API and QGIS host; the full manual browser approval initiated from QGIS still requires user acceptance testing.
General provider compatibility, high-client-count throughput, a stable SDK and OSDU-backed raster parity remain unqualified. The current native project service is the scientific authority. Connector identity API.
Signing in as another account does not silently change existing layer bindings. They retain their original authorization until explicitly reconnected.
The QGIS 0.5 pilot adds scientific context review and native result publication, qualified on QGIS 4.2.2. It creates separate derived assets and verifies exact no-op returns; it does not claim universal edit tracking or automatic vertical-datum conversion.
