Impersonation details - New feature request
Cantor, Scott
cantor.2 at osu.edu
Tue Oct 10 10:52:34 EDT 2017
> Personally, I cannot see why there would ever be a need for an
> impersonation implementation except for testing/development SP
> environments of an internal nature, for QA.
There are legitimate delegation scenarios that people tend to solve with impersonation because it's simpler, but this is not trying to solve that problem; it is as you say explicitly a feature for testing things and as such the applications rarely can be counted on to care about it or do anything to participate.
> As such, we have found our
> impersonation implementation to be a powerful tool for our authorized tech
> folks to use in development, testing, and even troubleshooting. Since Scott
> is calling this an intercept functionality, I am guessing that it will be easy to
> use RP override to predicate SP inclusion, at a minimum.
Even if it were enabled globally it won't do anything unless the configured logic returns accounts one can actually impersonate so it's easy to control this in a lot of different places.
I have no issue with Brad wanting to be able to signal something about this and I patched in an API change to facilitate doing that. I'm just not going to standardize that signal.
-- Scott
More information about the dev
mailing list