Impersonating Users October 9, 2026
I'm not sure how it's done elsewhere but this is how I've always done it
I built altarschedule.com almost two years ago. It's definitely done what I set out to do, which was to cut down on the 80 email threads that were happening, provide an easy to reference schedule, and give the tools to the person who is in charge of it to be able to do what they want.
However, my daughter has since graduated the grade school and is no longer an altar server. So I don't have the parent view on the live site. I, of course, can fire up the local site with all of my test users. But sometimes someone will report an issue and I just can't see what they're seeing anymore. And the live view of the site is what they're looking at, saying “it works on my machine” doesn't do it anymore in the day of cloud computing.
So I added in the impersonate feature in like an hour. Basically, the admin has a list of users. And I want to “log in” to the site with a specific user to be able to see what they're seeing, and in the case of a bug, try to reproduce it myself.
Basically, impersonate, to me, has always worked like this. It's clean. You get the user that you want to impersonate. You basically have another property within the site of the original user, and you overwrite the main user (the admin who's logged in) with the selected user, and store the admin user somehow as the “impersonator” user.
In altarschedule.com, this is in cookies.
Given two users: the admin user and the “parent” in this case (impUser)
impCookie := makeUserCookie(admin, impersonatorCookie)
uCookie := makeUserCookie(impUser, userCookie)
http.SetCookie(w, impCookie)
http.SetCookie(w, uCookie)
All of the site is set to look to the userCookie for who's logged in, so none of it has to be updated to deal with “impersonate” logic. You simply are that user now. The impersonator cookie holds the admin for when you want to stop impersonating. You simply get the user from the database specified in the impersonator cookie, and set the user cookie back to it. And you can remove the impersonator cookie so things like “isImpersonating” don't get confused.
That's it. Happy coding!