11
Allow logging-in to same account via multiple auth providers
Source: directus/directus#24868 · opened by @benhaynes
I know there are login security concerns based on how a Directus user account is created via an auth provider. However, there is also the precedent of using SSO as a convenience feature for logging in (not for registration). I would like to discuss and agree upon the ideal configuration options to balance all security and convenience. Account Creation • Admin Manually Create or Invites User • Local Registration via Public Form (with allow-list filtering) • Other Auth Providers, eg: SSO (with allow-list filtering) Account Authentication • Local Login Form • Auth Provider Flow • Magic Link (is this considered an Auth Provider?) I would like to support all combinations of the above (if at all possible) and offer configuration options to limit for security purposes. For instance, there should be options to individually disable local registration and login, and for limiting login to the service that created the account. We'll a…
No pledges yet. Be the first to back this.
Comments
Similar requests
Introduce UI-Based Configuration for OAuth/SSO Providers
7 votes · 0 comments
Allow replacement of S3 Bucket URL with a CDN URL
25 votes · 0 comments
Ability to login to directus using access token of a configured provider.
2 votes · 0 comments
A way for a hook to identify root calls
1 vote · 0 comments
Request origin isn't passed in the accountability object
1 vote · 0 comments
No comments yet.