Dexie Cloud: Allow DB owners impersonate users. #1866
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
To login as other user, the following format will be understood by the service: "yourEmail as targetEmail"
Example:
"[email protected] as [email protected]"
Allow this format in the login dialog. Server will validate whether the first email owns an API client with GLOBAL_READ and GLOBAL_WRITE access. If so, OTP will be sent to owner email but token will be given out with the access for the second email.
This will help reproducting issues and troubleshooting. Note that this is not a secutiry concern - the first user has full control over the database and access to read and manipulate the full database via REST or import/export anyway. This is just a tool to be able to reproduce customer issues by logging in as them and follow repro steps.