Impersonation details - New feature request
Mike Schwartz
mike at gluu.org
Tue Oct 10 10:38:18 EDT 2017
Yes agreed... impersonation is a trust model / workflow challenge.
I think UMA does a nice job of handling the explicit consent.
- Mike
On 2017-10-10 09:24, Cantor, Scott wrote:
>> I've always pushed back on the idea of impersonation using SAML or
>> OpenID Connect. Doesn't it undermine the integrity of the system if
>> someone else can login as you?
>
> There is nothing stopping anybody from configuring an IdP to do this
> today, it took me all of 8 hours work to create a relatively polished
> way to do it that took no system changes. What deployers choose to do
> or not do is a local policy question, I just want it done safely and
> not by mucking around with the authentication code. I think you're
> asking a deployment/trust/federation sort of question, it's not a
> software question.
>
>> I think it's possible with a user-initiated UMA claims gathering flow.
>
> Any solution involving the app is dead on arrival for most of the
> testing scenarios where this gets used. That's really a totally
> different use case.
>
> Note that Kerberos has had impersonation for most of its life.
>
> -- Scott
More information about the dev
mailing list