# Gedachten over het imiteren van een gebruiker

**URL:** https://meta.discourse.org/t/thoughts-about-impersonate-user/258795
**Category:** Community Building
**Tags:** impersonate
**Created:** [20 maart 2023 om 19:54 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795 "2023-03-20T19:54:52Z")
**Posts on this page:** 20
**Page:** 3

<div class="post-metadata">

### Author: ![satonotdead](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/satonotdead/32/447830_2.png) [@satonotdead](https://meta.discourse.org/u/satonotdead)
#### Post date: [21 maart 2023 om 15:02 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/47 "2023-03-21T15:02:47Z")

</div>

> [@Heliosurge](#):
>
> I am surprised at the resistance being presented to simply have options to limit or disable the function as a choice.

Could be social and/or cultural and I try to share my thoughts -not judging anyone- because of that.

Some people are living in countries that are resistant to changes and fully censored (so they could normalize things that are directly attacking freedom from different perspectives or cultures).

But Discourse wants to be the forum top platform over the world and I think that discussing around this kind of topics is always a good thing for everyone.

Thanks for the space. I hope it could be revised for not harm the use cases but neither the trust on Discourse from users and communities concerns 🙂

---

<div class="post-metadata">

### Author: ![satonotdead](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/satonotdead/32/447830_2.png) [@satonotdead](https://meta.discourse.org/u/satonotdead)
#### Post date: [21 maart 2023 om 15:05 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/48 "2023-03-21T15:05:12Z")

</div>

> [@awesomerobot](#):
>
> Removing the impersonate button does nothing to make your account more secure.

We are talking about to prevent eventually very bad uses in large communities and not harming the trust that users give to Discourse.

We are not talking about blind forums or prevent admins have the data because that’s impossible from the centralized base that uses a single database.

**I think that question fits very well in ‘YES but’ and not into ‘YES or NO’ debate.**

> [@RGJ](#):
>
> IMO that is the point of the topic: can and should you trust the admins of the communities you participate in?

Sorry but that’s not the point of my topic. You can open another one and ask whatever you want.

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [21 maart 2023 om 15:12 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/49 "2023-03-21T15:12:40Z")

</div>

> [@satonotdead](#):
>
> prevent eventually very bad uses in large communities and not harming the trust

I think you’re missing my point. It IS the point of the topic.

---

<div class="post-metadata">

### Author: ![awesomerobot](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/awesomerobot/32/142900_2.png) [@awesomerobot](https://meta.discourse.org/u/awesomerobot)
#### Post date: [21 maart 2023 om 15:15 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/50 "2023-03-21T15:15:01Z")

</div>

> [@satonotdead](#):
>
> We are talking about to prevent eventually very bad uses in large communities and not harming the trust that users give to Discourse.

Removing impersonate does not prevent this, it’s just as easy without it. The primary effect of removing impersonate would be making it harder to troubleshoot account specific issues.

---

<div class="post-metadata">

### Author: ![satonotdead](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/satonotdead/32/447830_2.png) [@satonotdead](https://meta.discourse.org/u/satonotdead)
#### Post date: [21 maart 2023 om 15:15 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/51 "2023-03-21T15:15:50Z")

</div>

> [@RGJ](#):
>
> I think you’re missing my point. It IS the point of the topic.

It don’t. Managing manually the database is totally different to click and post like another guy.

That’s enabled on default Discourse instance without clearly statments or universal use cases more than developer testing.

That’s the point on my thread. And sorry again, but you can open another thread or think whatever you want.

---

<div class="post-metadata">

### Author: ![awesomerobot](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/awesomerobot/32/142900_2.png) [@awesomerobot](https://meta.discourse.org/u/awesomerobot)
#### Post date: [21 maart 2023 om 15:16 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/52 "2023-03-21T15:16:30Z")

</div>

> [@satonotdead](#):
>
> Managing manually the database is totally different to click and post like another guy.

You should spin up a demo and try some of the admin features, you don’t need database access or impersonate to change someone’s words or read their messages.

---

<div class="post-metadata">

### Author: ![MikeNolan](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mikenolan/32/297597_2.png) [@MikeNolan](https://meta.discourse.org/u/MikeNolan)
#### Post date: [21 maart 2023 om 15:17 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/53 "2023-03-21T15:17:21Z")

</div>

> [@satonotdead](#):
>
> But the question is **why is only at one-click distance** when changing the title of trust levels implies the use of query explorer or managing the database manually?

If it’s one click or a dozen clicks, it makes little difference, it is still possible. I know someone who works from home frequently and has to go through about a half dozen passwords, two-factor IDs and other rigamarol to get into his company’s internal systems, but it only takes him a few minutes to do it.

Either you and your users trust the developers and administrators, or you/they don’t. And if you don’t trust the system, then how you use it will likely change.

---

<div class="post-metadata">

### Author: ![satonotdead](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/satonotdead/32/447830_2.png) [@satonotdead](https://meta.discourse.org/u/satonotdead)
#### Post date: [21 maart 2023 om 15:17 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/54 "2023-03-21T15:17:27Z")

</div>

> [@awesomerobot](#):
>
> The primary effect of removing impersonate would be making it harder to troubleshoot account specific issues.

From your perspective, of course 🙂

**From my perspective that probably validate that Discourse takes in mind about privacy and freedom.**

Managing manually a database is OK for a dev. A single button for every admin to impersonate is unnecesary and not OK.

_In the middle, there can be a simple system that shows in transparent way that impersonate was used or something like that._

I mean, you can think about options or reduce the whole thing to your own perspective.

---

<div class="post-metadata">

### Author: ![awesomerobot](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/awesomerobot/32/142900_2.png) [@awesomerobot](https://meta.discourse.org/u/awesomerobot)
#### Post date: [21 maart 2023 om 15:18 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/55 "2023-03-21T15:18:46Z")

</div>

You need to go back and read my last few posts before responding again, admins can still do all of this without impersonate or database access. Impersonate and most admin actions are already logged in the event that an other admin needs to have a trail to find a malicious admin.

---

<div class="post-metadata">

### Author: ![Heliosurge](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/heliosurge/32/571810_2.png) [@Heliosurge](https://meta.discourse.org/u/Heliosurge)
#### Post date: [21 maart 2023 om 15:27 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/56 "2023-03-21T15:27:08Z")

</div>

> [@awesomerobot](#):
>
> If you can’t trust an admin out of fear that they’ll read your personal messages or alter what you post to harm you, you should not use the site.

Or simply close that open function with the Encrypt plugin. At the end of the day having options on functions ppl might find problematic is a good thing. False sense of security, safety etc.. Only secure system to Quote Adama is an offline terminal that os not networked to other systems.

All the pros for and m cons against have valid PoV. Compromise is the best solution for all parties. Encrypt Plugin I imagine was developed to appease the desire and in some places a possibly a requirement to have a layer of privacy to the PM/DM subsystem.

Perhaps if not put into Core as an option maybe a plugin that accomplishes the desired effect for those say Self Hosted systems that want the peace of mind.

One could say the script for making custom badges does not need be disabled as only the Admin has direct access to make them. However this has to be enabled from Root unlesd that has changed.

* * *

I agree in perfect ideal circumstances ppl should be able to trust ppl in positions. Unfortunate trust is at times misplaced and only found on discovery.

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [21 maart 2023 om 15:33 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/57 "2023-03-21T15:33:43Z")

</div>

> [@Heliosurge](#):
>
> One could say the script for making custom badges does not need be disabled as only the Admin has direct access to make them. However this has to be enabled from Root unlesd that has changed.

That’s a performance measure, to make sure that hosted customers on a shared environment cannot bring each others site to its knees. It makes it possible to distinguish between the server admin and the forum admin.

---

<div class="post-metadata">

### Author: ![satonotdead](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/satonotdead/32/447830_2.png) [@satonotdead](https://meta.discourse.org/u/satonotdead)
#### Post date: [21 maart 2023 om 15:51 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/58 "2023-03-21T15:51:51Z")

</div>

> [@MikeNolan](#):
>
> If it’s one click or a dozen clicks, it makes little difference, it is still possible.

Clicking once or dozen seems to be similar but is not the same and because of that a lot of corporations loose a lot of money for not enabling a simple button saying ‘Unsubscribe me’.

We probably are talking about the opposite but from moral and ethics PoV.

> [@awesomerobot](#):
>
> You should spin up a demo and try some of the admin features, you don’t need database access or impersonate to change someone’s words or read their messages.

I’m using Discourse as admin from 4 years ago and I know what you are talking (totally different cases from impersonating users).

What you said not enable the possibility to post like another with one single click. That’s like using a third party IP or ID and is different than editing their posts for moderation.

_BTW I hope that encryption stop and breaks the possibility to read users PMs but that’s for another thread and I’m waiting for updates for test 🙂_

---

<div class="post-metadata">

### Author: ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### Post date: [21 maart 2023 om 16:26 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/59 "2023-03-21T16:26:57Z")

</div>

I’ll quote this again as it looks like you’ve gone and got slow mode added… 🙂

> [@Thoughts about impersonate user](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/26):
>
> Just a polite reminder from your friendly neighbourhood moderator to keep the discussion civil, and generally cool, calm and collected. pray Debating Discourse features should not be a fraught experience. slight_smile

> [@satonotdead](#):
>
> What you said not enable the possibility to post like another with one single click. That’s like using a third party IP or ID and is different than editing their posts for moderation.

I’ve been toying with the idea of some practical examples of ‘change ownership’ and/or ‘edit your post and hide the revision’ to demonstrate that this is mainly a moot argument as to the method used to make it look like you said something you didn’t without touching the impersonate button, but I have decided against it. 🙂

But there are certainly more than a few ways I could be an absolute arse with all the magic buttons I have just in the UI, let alone playing with the rails console. I think a lot relies on the trust of the community, not just the admin as lots of these features are available at TL4/catmod/mod level as well. I think in general the ‘staff’ group generally don’t go out of their way to be destructive with any of the tools as it would be an act of self-sabotage on their own community.

As such, I don’t know why the impersonate feature itself is being singled out as unethical?

But let me leave you with this… 🙂

> [@satonotdead](#):
>
> Sorry for the aggro everyone 🙏

---

<div class="post-metadata">

### Author: ![kynic](https://avatars.discourse-cdn.com/v4/letter/k/b487fb/32.png) [@kynic](https://meta.discourse.org/u/kynic)
#### Post date: [21 maart 2023 om 16:39 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/60 "2023-03-21T16:39:22Z")

</div>

> [@satonotdead](#):
>
> We are not talking about Google, Facebook or Apple. We are talking about Discourse that’s open-source and allow self-hosting.
> 
> That’s supposed to be the oppossite.

Seriously, all of these comments which claims misuse and other stuff does not make sense to me, there is no point to disable this particular feature. An admin still can do everything as others pointed.

But then, still you don’t want to hear others and want to make an issue out of nothing. I still don’t understand what truly is the problem. You will lose your users? Or you have fear that your other admin will use this feature against you? If so, then you should not make admins whom you don’t trust as simple as that.

---

<div class="post-metadata">

### Author: ![Heliosurge](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/heliosurge/32/571810_2.png) [@Heliosurge](https://meta.discourse.org/u/Heliosurge)
#### Post date: [21 maart 2023 om 16:55 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/61 "2023-03-21T16:55:24Z")

</div>

> [@RGJ](#):
>
> That’s a performance measure, to make sure that hosted customers on a shared environment cannot bring each others site to its knees. It makes it possible to distinguish between the server admin and the forum admin.

I will be perfectly honest Richard, you and @merefield have very valid positive use scenarios. But I feel you both are only seeing how changing elements with optional settings would impede yoyr workflows. Which it really wouldn’t as with if your providing hosting the feature would not change for either of you.

Save for example if I were to posted a problem I needed help with with agreements for monetary compensation or pro bono. You or Robert or anyone that offers help can layout the tools required from a self hosted Discourse.

ie. "Dan I can help you for $X to solve your issue. I will the need the following. To create an account on your site and granted Admin access, I will also need to access Impersonate( with a list of users okay to use the feature on so I can properly and efficiently diagnose and fix the issue.. If you have Impersonate disabled you will need your root admin to enable it. If you agree to my terms we can get this process started. "

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [21 maart 2023 om 16:59 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/62 "2023-03-21T16:59:36Z")

</div>

> [@Heliosurge](#):
>
> But I feel you both are only seeing how changing elements with optional settings would impede yoyr workflows.

I’d automate that, so I’m not worried about that at all (in fact, I have a shell script that takes the host name and the username of a Discourse install hosted by us as an argument, and it gives me a login link (including 2FA and logging).

I’ve already explained my objections over two hours ago (but I’ll gladly repeat them to avoid further confusion about my motives)

> [@RGJ](#):
>
> My “resistance” is twofold:
> 
> - removing the feature or making it harder to access provides a false sense of security
> - when such functionality is hard(er) to access support personnel finds their way around it, and sharing passwords is much worse, since that’s not logged, passwords can be kept around, and passwords can be valid for other services.

---

<div class="post-metadata">

### Author: ![jimkleiber](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jimkleiber/32/121814_2.png) [@jimkleiber](https://meta.discourse.org/u/jimkleiber)
#### Post date: [21 maart 2023 om 17:55 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/63 "2023-03-21T17:55:59Z")

</div>

In my best attempt to manually GPT-4 summarize what I’m reading:

- Some want higher friction to impersonate
- Some want the current level of low friction to impersonate

For those who want a little more friction (I’m in that camp, because I personally don’t want to be tempted to click the button, similar to Screen Time and other tricks on iOS to help me avoid temptation):

- Add a very simple theme component to your site with the following CSS:

```plaintext
.btn-impersonate {
  display: none;
}

```

Perhaps you want even more friction than that, and maybe someone could make a plugin or more advanced theme component to do it, but I want to try this out and see if it provides me enough friction to avoid any unwanted temptation.

---

<div class="post-metadata">

### Author: ![renato](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/renato/32/383632_2.png) [@renato](https://meta.discourse.org/u/renato)
#### Post date: [21 maart 2023 om 20:24 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/64 "2023-03-21T20:24:48Z")

</div>

> [@JammyDodger](#):
>
> I’ve been toying with the idea of some practical examples of ‘change ownership’ and/or ‘edit your post and hide the revision’ to demonstrate that this is mainly a moot argument

To me, this is the main point. Admins can still “impersonate” users with the other available tools, literally a few clicks away.

But in the end of the day, Discourse is an open-source project with a plugin system, you can always make things work the way you think is right for your own community.

If you want a plugin, I would start with one overriding `Guardian.can_impersonate?`, it’s used by the serializer that determines the presence of the Impersonate button as well as by the backend checks. At least from a quick test on my dev instance, it worked:

```ruby
# plugin.rb
after_initialize do
  class ::Guardian
    def can_impersonate?(target)
      false
    end
  end
end

```

---

<div class="post-metadata">

### Author: ![Canapin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/canapin/32/119591_2.png) [@Canapin](https://meta.discourse.org/u/Canapin)
#### Post date: [21 maart 2023 om 21:34 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/65 "2023-03-21T21:34:21Z")

</div>

> [@jimkleiber](#):
>
> because I personally don’t want to be tempted to click the button

> [@renato](#):
>
> But in the end of the day, Discourse is an open-source project with a plugin system, you can always make things work the way you think is right for your own community.

A somewhat related (to some extent) topic, though it’s not about temptation, but rather using an sensitive feature without realizing we’re using it or by mistake (reading a user’s PM): [Add a warning when checking personal messages from a user public profile, as an admin](https://meta.discourse.org/t/add-a-warning-when-checking-direct-messages-from-a-user-public-profile-as-an-admin/215630)

I share two experiences, one is written in the first post and the other is here: [Add a warning when checking personal messages from a user public profile, as an admin - #11 by Canapin](https://meta.discourse.org/t/add-a-warning-when-checking-direct-messages-from-a-user-public-profile-as-an-admin/215630/11)

---

<div class="post-metadata">

### Author: ![jimkleiber](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jimkleiber/32/121814_2.png) [@jimkleiber](https://meta.discourse.org/u/jimkleiber)
#### Post date: [21 maart 2023 om 21:55 UTC](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795/66 "2023-03-21T21:55:03Z")

</div>

…I did not know I could so easily click on any user’s full list of messages from their profile…

Yes, another reason why I like Discourse Encrypt and would love for it to be extended to personal/private chats as well.

Although, it doesn’t seem to be as easy for me as an admin to view a user’s personal chats, but is it?

[Vorige pagina](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795.md?page=2)

[Volgende pagina](https://meta.discourse.org/t/thoughts-about-impersonate-user/258795.md?page=4)
