How do we avoid closing the door to federation? #10
Labels
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
spoons.technology/plots#10
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
I suspect having an identity that can be migrated is one of those baffling problems that intersects tech and psychology. However, it feels good to contemplate how we might allow people to run a similar co-op and mutually share services.
Perhaps we could experiment via the RoW directory? Or perhaps we explicitly build a separate ID service at some point?
Did an experiment setting RoW and Spoons keycloak to have the other as an identity provider. It pretty much just works, though so far I've only tested with users that exist on both sides. If you have the same email on both sides, then keycloak links your accounts - so you're the same user but authenticating via a different service.
Would need a bit more poking, but it looks from a brief play that it would be really doable for a similar project to federate with spoons by linking auth services (authn), then adding access later via groups (authz).