Speaker
Dmitry Egorov
(MAX IV)
Description
Tango Controls features a client-side access control system that verifies users through system accounts and can restrict access based on IP addresses. However, this method lacks flexibility, as it relies on system accounts and is relatively easy to bypass.
In addition to the existing access control, a server-side authorization system was developed at JINR, allowing roles and sessions to be managed while logging all actions of authorized users.
The presentation covers the current usage of the system, its limitations, and potential starting points for discussion and integration of this system into Tango Controls.