Question about initial user/role setup after enabling SAML SSO

Erdos, Marlena marlena_erdos at harvard.edu
Mon May 6 18:10:09 EDT 2013


Yaowen Tu wrote: 

>>We are a service provider, and we are using Shibboleth SP. Suppose in
>>our application, we originally have our own user/role management.
>>Different users with different roles are allowed to use different
>>features. So that when a user login we need to know which roles this
>>user has, and prepare appropriate UI. We have administrator role, users
>>with this role can assign roles to other users.
>>

David Langenberg wrote:

>....  Now, the one request I would make if you do go this route is to NOT
>require that a user have only ONE single role.  Rather, be able to handle
>the case of a user coming in with more than one role applied to them.  If
>two roles are completely orthogonal to each-other use a UI element in the
>application to allow the user to choose which role they'd like to use for
>this session.
>



Or alternatively, use a different url for admin actions and user actions.
 And then avoid having the user have to choose the role they want.
Either way  though (user selection of role or different url) it's
"important." 

Yours for least privilege :-),
Marlena
PS http://en.wikipedia.org/wiki/Principle_of_least_privilege





More information about the users mailing list