I start to feel a little safer on the code and some auth related issues came up:
• are we sure we want to keep users and admins the same resource?
• Wouldn’t it be better to separate users and admins to avoid privilege escalation?
k
kennyadsl
02/10/2025, 8:15 AM
We discussed this several times in the past, and I think we are all open to it.
m
mamhoff
02/10/2025, 8:33 AM
Solidus' user system is configurable. It shouldn't be too hard to add a second configurable user resource. The admin user should not be part of the core distribution, just like the current user implementation is not.