Page MenuHomePhorge

Allow a "sharing domain" to be supplied alongside the "email address domain name space"
Closed, ResolvedPublic

Description

When managers of group accounts have multiple alias or child domain name spaces, the email address they choose for their users implies the authorization realm in which these users will reside. Effectively, this prevents two individual users whom are associated with the same group manager account to share information among themselves.

So, an admin@example.org could have a child domain example.ch. Creating John as john@example.org and Jane as jane@example.ch will prevent John (user/john@example.org) and Jane (user/jane@example.ch) from sharing content between them (crossing the boundary between the example.org and example.ch authorization realms is not allowed).

Using a (realmed) result attribute different from the primary email recipient address (to name the mailbox and canonify the login username to) could resolve this issue, and allow John and Jane to share content.

However, this strict boundary between authorization realms may, at times, be the desired -- such as for a reseller with company.de and competitor.nl as customers.

The introduction of a "sharing domain" for the HKCCP group manager user management forms could resolve the issue. The administrator can then, separately from the primary email recipient address, choose the authorization realm in which the mailbox and therefore the user's login should be put.

Details

Ticket Type
Task

Revisions and Commits

Event Timeline

vanmeeuwen claimed this task.
vanmeeuwen raised the priority of this task from to 60.
vanmeeuwen updated the task description. (Show Details)
vanmeeuwen added a project: Restricted Project.
vanmeeuwen moved this task to Restricted Project Column on the Restricted Project board.
vanmeeuwen changed Ticket Type from Task to Task.
vanmeeuwen moved this task from Restricted Project Column to Restricted Project Column on the Restricted Project board.
vanmeeuwen added subscribers: vanmeeuwen, seigo, vincent.
vanmeeuwen added a revision: Restricted Differential Revision.Sep 15 2015, 1:44 PM