I start to feel a little safer on the code and som...
# general
f
I start to feel a little safer on the code and some auth related issues came up: • are we sure we want to keep users and admins the same resource? • Wouldn’t it be better to separate users and admins to avoid privilege escalation?
k
We discussed this several times in the past, and I think we are all open to it.
m
Solidus' user system is configurable. It shouldn't be too hard to add a second configurable user resource. The admin user should not be part of the core distribution, just like the current user implementation is not.
f
should not be part of the core distribution
Can you elaborate on that?