2
Make public user registratation more difficult to activate
Source: directus/directus#24661 · opened by @chrney
Summary I would like to propose enhancements to the public user registration feature to prevent accidental activation, which can lead to unauthorized account creation or, in worst-case scenarios, the unintended assignment of admin rights. Strengthening safeguards around this setting would help ensure it is only enabled intentionally, thereby reducing potential security risks. Basic Example _No response_ Motivation Why this Is Important • Prevent accidental access: accidental activation could result in unwanted accounts and potential data exposure. • Mitigate security Risks: misconfigured permissions could unintentionally grant administrative privileges to public users, compromising system integrity. This has happened, and since these admin accounts have been of unknown origin, we had to make huge investigations on how these were created. • Ensure compliance: many organizations must meet strict security and privacy regulations, and unintentional public reg…
No pledges yet. Be the first to back this.
Comments
Similar requests
Public policy doesn't show restricted role count
1 vote · 0 comments
Can't assign Public role from a policy
1 vote · 0 comments
Limit public permission by custom API parameter
1 vote · 0 comments
Filter usability - choose whether a group should appear in the filters
14 votes · 0 comments
Improve Flows display
5 votes · 0 comments
No comments yet.