|
|
|
|
|
by zkmon
18 hours ago
|
|
Absolutely. A service has no business to know who you are. They should only care if the user has authorization. Authentication has historical reasons. Employee access, citizen services etc all are identity based. Identity was translated into authorisation for multiple services instead of each service requiring it's own authorisation. |
|