Impersonation details - New feature request

Mike Schwartz mike at gluu.org
Tue Oct 10 10:14:12 EDT 2017


Shib Devs,

I've always pushed back on the idea of impersonation using SAML or 
OpenID Connect. Doesn't it undermine the integrity of the system if 
someone else can login as you?

I think it's possible with a user-initiated UMA claims gathering flow.

- Mike


On 2017-10-09 15:21, Cantor, Scott wrote:
> On 10/9/17, 2:58 PM, "dev on behalf of Schwoerer, Brad"
> <dev-bounces at shibboleth.net on behalf of schwoerb at uww.edu> wrote:
> 
>> I agree that I want to make this simple, I just couldn't think of an 
>> elegant user flow.  Ideal would be a way to have a user initiate
>> an impersonated/onbehalfof session without interupting every 
>> authentication flow for the user to have a chance to choose that
>> they want to have this session for this app be impersonated.
> 
> I think that's a feature. Silently switching is not a good thing IMHO.
> 
> -- Scott


More information about the dev mailing list