3 ms·
> Whenever possible, use the email as the user identifier. You can manage with any other kind of identifier, but debugging is significantly easier, since you do
by davewritescode 7y ago
> Whenever possible, use the email as the user identifier. You can manage with any other kind of identifier, but debugging is significantly easier, since you don't have access to the customer's IdP to know the correspondance between an actual user and its opaque identifier.
This isn't a great idea, things like email get recycled fairly frequently. Some systems also let people change their email, for example, it's not uncommon for an email to change when someone gets married or for an email to get recycled when an employee leaves a company.
> In the end, we've found it far easier to use SAML only for authentication, and to implement an RBAC on our side, based on the identity of the users.
This I 100% agree with, standardizing basic attributes is hard enough.