personium / personium-core

Core module of Personium
https://personium.io
Apache License 2.0
88 stars 16 forks source link

Limit Unit User privilege #66

Closed shimono closed 6 years ago

shimono commented 6 years ago

Background

Currently unit users behave like super users and can do anything on the cell they have created. But it is problematic for actual PDS Provider to be able to read the CONTENTS of PDSs provided for its customers.

Remedy Spec Draft Idea

Also use Unit User Roles to keep backward compatibility. More specifically, change the meaning of "unitAdmin" and create new Unit User Roles.

UnitAdmin

CellContentsReader

CellContentsAdmin

Importance

SawamiWataru commented 6 years ago

Released in 1.6.4.