Great! Important functionality. It got much better!
Will “Developer” users be able to create/enable “Project Member”? If yes, great!
I still think administering the Thinger Server with a “Domain Admin” account to create devices, users, projects… something risky, as we don’t have Two-Factor Authentication (2FA).
I could be wrong, but it would feel safer to operate the Server in production with the “Developer” account that doesn’t allow changing HOST and domain settings.
But like I said, I could be wrong… except for the need to implement a Two-Factor Authentication (2FA).
Could you give more details about this functionality?
I remember that it would be important to change the device statuses to indicate, for example, when the device is disabled. With this, the Administrator could differentiate the status “Disconnected” from “Enabled/Dsabled”. I even mentioned it in this post:
Is it related to the device’s playload (Arduino-Thinger)?
It was a doubt I had (if I understand this point correctly). It was unclear whether establishing broad permissions for a “Project Member” would cause a security breach. Ex: Allow a “Project Member” to create and delete devices.
Sorry if I misunderstood this point.