Impersonation details - New feature request
O'Dowd, Josh
Josh.O'Dowd at mso.umt.edu
Tue Oct 10 10:39:01 EDT 2017
>>I've always pushed back on the idea of impersonation using SAML or
>OpenID Connect. Doesn't it undermine the integrity of the system if
>someone else can login as you?
>
>I think it's possible with a user-initiated UMA claims gathering flow.
>> I would agree if the IDP doesn't offer a way to communicate it to the app, or exclude an app on the SPs request. Like all things, it will take time for the apps to catch up to the functionality, but I think it is necessary moving forward. This is why I think it is important, as an implementer, to only enable it on an app-by-app basis. There needs to be a way for an SP to not to want to accept. Until there are profiles and the such, that is on IDP side to not allow it for a particular app.
Personally, I cannot see why there would ever be a need for an impersonation implementation except for testing/development SP environments of an internal nature, for QA. As such, we have found our impersonation implementation to be a powerful tool for our authorized tech folks to use in development, testing, and even troubleshooting. Since Scott is calling this an intercept functionality, I am guessing that it will be easy to use RP override to predicate SP inclusion, at a minimum.
Josh
More information about the dev
mailing list