I'm setting up a Multi-tenant app and ran into an issue.
I want to use the users EMAIL as their login name. But this causes the following problem.
Let's assume there are a 1000 Franchise stores individually owned. The admin sets up a staff user, using their email. No problem.
Now the staff user leaves, and goes to work for another of the Franchise stores. So if the user was not deleted from the original Franchise, when te logs in in, he would be getting into the original store. I can't assume that the original store admin will remove the employee. Now that I think about it, the user is already setup in the system, and has a password. So it brings up issues, do we create the user again with the store id, and new password (not even sure AIM lets you have the same username in more then once).
Login names (non email would work but Email logins are much easier)
A couple ideas I had:
When the user logs in, it can do a firstcommand and display a list of stores that they are registered in, and they can select the one they want to work in. From there we just use their tenant id for everything. However that still leaves a password issue. (not sure how to handle this).
Another idea which I don't know if possible, is during login, is for the User to enter their store id, email, and password. But now they have to remember a store id as well and you have to have recovery for that as well.
Just as a note: I setup in another application one of my companies using my email. Then I have another independent company which I setup and used the same email. They use a URL system and change it slightly for each company. When you put in your email, the display a list of companies to log into. In AIM maybe, do the same?
A standard login (non email) resolves these issues as it wouldn't let a store create the same users login name. Email name with a Tenant ID on initial login but AIM only allows username and password.
Just email is the best and if we can get a good method, it would enhance the SaaS capability of AIM.
Wracking my brain on this one but the handling the login for muti-tenancy has to be good and secure. I just may have to go to a user name, but don't want to.
Thanks in advance for any suggestions.
Mark