Impersonation details - New feature request
Cantor, Scott
cantor.2 at osu.edu
Tue Oct 10 10:24:29 EDT 2017
> I've always pushed back on the idea of impersonation using SAML or
> OpenID Connect. Doesn't it undermine the integrity of the system if
> someone else can login as you?
There is nothing stopping anybody from configuring an IdP to do this today, it took me all of 8 hours work to create a relatively polished way to do it that took no system changes. What deployers choose to do or not do is a local policy question, I just want it done safely and not by mucking around with the authentication code. I think you're asking a deployment/trust/federation sort of question, it's not a software question.
> I think it's possible with a user-initiated UMA claims gathering flow.
Any solution involving the app is dead on arrival for most of the testing scenarios where this gets used. That's really a totally different use case.
Note that Kerberos has had impersonation for most of its life.
-- Scott
More information about the dev
mailing list