-
Notifications
You must be signed in to change notification settings - Fork 40
Open
Labels
enhancementNew feature or requestNew feature or request
Description
If a user is added through Oauth, or merges to oauth login and is subsequently deactivated in the central
IdP this deactivation does not propagate to Redmine.
Imagine this case:
- User exists in Redmine
- Admin migrates to oauth login (by tightening password rules that much, its uncomfortable to login using password)
- User gets centrally deactivated in the Oauth provider
- User still is able to change its password and login to redmine
I don't know what a proper solution would be to propagate the deactivation of the user to redmine,
and its interesting for other SSO services too. You would expect, that by centrally disabling a user
it becomes inactive on all connected services, or wouldn't you?
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request