Skip to content

the groups of sso are global on LAIN #2

@wchaoyi

Description

@wchaoyi

For now, the authorization of LAIN's app (eg. console) is based on groups of sso, i.e. some user in the group having the competence which can be understood as different permission for all clients using this group, which is hardly to have the user‘s consent. The authorization depends on who is the user, not what the user authorizes.

So, the SSO's admin should be careful for the clients of sso, since some evil client will using the user's potential authority such as undeploy a app and get the secret files of a app.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions