Skip to content

[Q] How do I limit the domains if I enable sso #2619

Closed Answered by matmair
nwns asked this question in Q&A
Discussion options

You must be logged in to vote

@nwns I would block this at the authentication level to be safe.
Instead of using the google provider try using open id and add the hosted domain parameter.
Would much prefer to handle things like this in config and not add code for more checks. There are some many ways to get those wrong.

Also please use discussions for questions, issues are more for FRs or bugs - discussions (QA type) are better for our SEO and threading is much more readable there.

Replies: 1 comment 13 replies

Comment options

You must be logged in to vote
13 replies
@matmair
Comment options

@matmair
Comment options

@blieb
Comment options

@matmair
Comment options

@blieb
Comment options

Answer selected by matmair
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
question This is a question security Relates to a security issue
3 participants
Converted from issue

This discussion was converted from issue #2602 on February 11, 2022 22:57.