Uploaded image for project: 'Syncope'
  1. Syncope
  2. SYNCOPE-1630

Use Group owners to extend Delegated Administration

Attach filesAttach ScreenshotVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

    Details

    • Type: Improvement
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 2.1.10, 3.0.0
    • Component/s: console, core, documentation
    • Labels:
      None

      Description

      Currently, Delegated Aministration is based on Realms and Dynamic Realms.

      The former is quite static but widely used; the latter is extremely flexible but not used in any deployment, in practice, because it quickly becomes slow with real numbers.

      An idea is to put in place some form of group-based authorization model: user A is allowed to administer user B if (a) B is member of group G (b) A is owner of G.
      One advantage of such approach is that no changes in persistence would be needed.

        Attachments

          Activity

            People

            • Assignee:
              ilgrosso Francesco Chicchiriccò
              Reporter:
              ilgrosso Francesco Chicchiriccò

              Dates

              • Created:
                Updated:
                Resolved:

                Issue deployment