Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

the groups of sso are global on LAIN #2

Open
wchaoyi opened this issue May 19, 2016 · 0 comments
Open

the groups of sso are global on LAIN #2

wchaoyi opened this issue May 19, 2016 · 0 comments

Comments

@wchaoyi
Copy link
Member

wchaoyi commented May 19, 2016

For now, the authorization of LAIN's app (eg. console) is based on groups of sso, i.e. some user in the group having the competence which can be understood as different permission for all clients using this group, which is hardly to have the user‘s consent. The authorization depends on who is the user, not what the user authorizes.

So, the SSO's admin should be careful for the clients of sso, since some evil client will using the user's potential authority such as undeploy a app and get the secret files of a app.

@wchaoyi wchaoyi changed the title the groups of sso are global the groups of sso are global on LAIN May 19, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant