OpenConext / OpenConext-dashboard

Dashboard for IdP administrators to view and adminster SP connections
Apache License 2.0
8 stars 12 forks source link

Implement real impersonation #586

Open phavekes opened 1 week ago

phavekes commented 1 week ago

This issue is imported from pivotal - Originaly created at Mar 15, 2024 by Bart Geesink

When a user impersonates a SURFconextverantwoordelijke, the user is not really impersonated. This makes that various authorization decisions (like restricting what a super admin may do) are still applied. Really impersonating the user would remove these restrictions.

phavekes commented 1 week ago

We\'ll make a better story (Bart Geesink - Apr 11, 2024)