3 ms·
Seems with this approach it should be easy for an admin to 'su' to a normal user account and perform actions as that user. Nice for tech support and other admin
by ch 15y ago
Seems with this approach it should be easy for an admin to 'su' to a normal user account and perform actions as that user. Nice for tech support and other administrative operations.
- choxi 15y agowow that's a great idea, I hadn't thought of that! I guess that's just another benefit of dissociating the identity (Identity) from the login (User).
- ch 15y agoThis is typically why you separate authentication and authorization. In your case many authenticated users can be authorized to access a single identity.
- roel_v 15y agoHow would you divide the two? I'd say that 'identity' and 'user' are the same, that the things you'd want to dissociate are the ('roles' | 'permission set' | 'authorization rules') from the ('identity' | 'user' | 'login'). But in that case, it wouldn't help with anonymous sessions - unless you'd just define those as new 'identities' with many of the properties set to unknown. I think the pattern is interesting enough to flesh out, but I'm not convinced yet if it's a real change from the traditional user/permission duality that is already in wide use.