1
Move SSO_CLIENT_SECRET to the Read Only Admin Panel or Encrypt it
Source: dani-garcia/vaultwarden#6791 · opened by @jobritz
Hey there, as I was an SSO user before the merge in this main image I was really happy, that this feature was finally merged. Before the merge I remember that there was a discussion about the location of the SSO settings in the Admin Panel. During the test phase I remember that the SSP Client Secret was located in the read only section, but now it is located in the SSO section where it can be edited without the need of a restart. Though I understand that reasoning I want to ask you to consider to move the SSO Client Secret either in the Read Only section of the Admin Panel or alternativly add some encryption as it is already done with the Admin Token. Right now, if I save my configuration in the Admin Panel, the SSO Client Secret appears in the config.json file as an unencrpyted value. When the Client Secret was located in the read only section, I included it with a podman secret, which was working fine. I am doing the same for my database url, which is not present in the config…
No pledges yet. Be the first to back this.
Comments
Similar requests
Set different entries for the Admin panel
1 vote · 0 comments
Argon2 for local master password hashing (not encryption key derivation)
4 votes · 0 comments
Feature: Auto-provision new users on first SSO login (no manual admin invite required)
1 vote · 0 comments
change the port for the admin account
2 votes · 0 comments
Multiple domains support, per organization
2 votes · 0 comments
No comments yet.