Skip to content

Gold doesn't offer the @idir username - Why and what should I consider? #138

Closed Answered by junminahn
zsamji asked this question in Gold Q&A
Discussion options

You must be logged in to vote

I believe many teams make use of IDIR username in their applications, and IDIR username is rather human-readable and is believed as a unique identifier for a specific IDIR user. As a matter of fact, it is unique in the system, and yet, there is a security risk to giving privileges based on it at the application level in terms of the IDIR username being re-used.
Therefore, even though IDIR username can be found in a token payload attribute idir_username of the Gold integration, it is highly recommended to use IDIR GUID in applications by mapping to preferred_username or idir_user_guid attributes as a source of truth for the IDIR user.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by arcshiftsolutions
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants