Skip to content

Discussion: Status after oauth user deactivation #56

@col-panic

Description

@col-panic

If a user is added through Oauth, or merges to oauth login and is subsequently deactivated in the central
IdP this deactivation does not propagate to Redmine.

Imagine this case:

  1. User exists in Redmine
  2. Admin migrates to oauth login (by tightening password rules that much, its uncomfortable to login using password)
  3. User gets centrally deactivated in the Oauth provider
  4. User still is able to change its password and login to redmine

I don't know what a proper solution would be to propagate the deactivation of the user to redmine,
and its interesting for other SSO services too. You would expect, that by centrally disabling a user
it becomes inactive on all connected services, or wouldn't you?

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions