[Lvfs-announce] Two important changes on the LVFS

Richard Hughes <[email protected]> Fri, 23 Mar 2018 20:47:31 +0000
Newsgroups dev.linux.lists.lvfs-announce
Message-ID <CAD2FfiGwLGy9+hj89dUk8zLDFUu4_B7A5759zXr+=kxJBbrMwQ@mail.gmail.com>
Hello and welcome!

I wanted to tell you all about two new features we've added to the
LVFS last week:

* The first important change is a new user level in the LVFS, one of a
"manager". A manger is able to create and delete accounts on the LVFS
within the specific "vendor group" so you can create multiple accounts
that map to people in your team rather than sharing a login between
multiple people or even between your ODMs. If you want to become a
"manager" in your vendor group, please ask me and I'll "promote" you
on the LVFS. A manager obviously has more permissions than just a
user, so if you don't need this facility then it's fine to carry on as
you are.

* The second additional feature is the ability to log in using OAuth.
We've added support for logging in using Microsoft AD, but I'm happy
to add support for different authentication providers if required. If
you want to use this functionality, please let me know and I'll set
this up for you to test.

As a consequence of both these changes, we're slowly switching from a
"username" based login system to an "email" based login system. For
instance, I used to login as "hughski" and now I log in as
"[email protected]" -- with the existing password unchanged. Both the
email and username methods will continue to work for many months, so
you don't have to change any procedures already put in place just yet.
If you log in using your existing username now it will tell you the
email address it would ideally like you to use in the future. The idea
here is that users on the LVFS should map 1:1 to people, rather than
mapped to OEMs or ODMs. This allows us to audit who-did-what, and also
allows us to better conform with the upcoming GDPR privacy
legislation.

If you have any questions, concerns, or comments, please let me know
and I'll respond in private.

Richard.