Why fetching impersonation is only if user is logged?
m7moud opened this issue · 2 comments
m7moud commented
I'm using different models for users and admins, and of course admins can impersonate users.
unregistered commented
+1... I didn't realize this was a dealbreaker before I started using this module.
ankane commented
This is done to prevent a situation where a user (who let's say is an admin) logs out but the impersonation sticks, so the next user who logs in on the same machine (who may not be an admin) will be impersonating (security issue).