Problem
We're introducing revisions for most content entity types in core (see #2745619: [policy, no patch] Which core entities get revisions?). But we're lacking a strategy for how users should be revisioned (or if they should be, at all).
Let's discuss!
Background
In a meeting on June 9 2016 in London (brief summary here #2721129-42: Workflow Initiative) it was decided that we would leave user revisioning out of scope for the Workflow Initiative. The reasoning was:
- Due to the lack of separation of account-type data, authentication-type data and profile-type data it gets very difficult to decide what to revision (e.g. what can be rolled back etc.)
- The main reason why Workflow Initiative is introducing revisioning is to facilitate replication/deployment of content across workspaces and across sites. And we don't want to replicate user accounts across these environments for security and privacy reasons. Account management should be explicitly handled. For example, user accounts can be replicated without knowledge to new environments where they aren't wanted.
For the above reasons, the Deploy suite of modules does not make users revisionable nor replicatable.
From #2745619-21: [policy, no patch] Which core entities get revisions?
There is information in the user entity that can/should be revisionable (like e-mail addresses for example, or user name, at the moment we only have current and init for mail and nothing for name). The idea of reverting a user entity revision is frightening, but I don't think this issue conclusively makes some kind of revision for support for users in core a hard 'no'.
Comments
Comment #2
dixon_IMO, we should introduce a new content entity type called "profile" (or something like that) that holds all data that can/should be revisioned, like the user name, profile picture and other profile-like fields.
There needs to be a clear separation from the entity that we use for authentication and authorization.
This will also create a logical separation of what user data that we can deploy/replicate between environments. E.g. we don't want to replicate the account data, just the profile data.
Comment #3
dpiThere is an earlier discussion. Probably want to merge this into that.
Comment #4
jayelless commented#2688559: Make the User entity revisionable
Comment #5
jayelless commented