Figure out how to have SSO only give basic forgejo permissions #28
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
we have this already right? the sso currently only gives triage permissions to a group which we have simply assigned everyone in beta to
Ah, I phrased this badly.
This was supposed to be an epic for making sure SSO doesn't do other things for generic GH logged-in users -- e.g. making sure our various services don't incorrectly treat "got a login token" as letting people e.g. see some of the SSO-gated webpages.
This wasn't "do this on forgejo"; this was "make sure nothing else is configured wrong".
Closing this as auditing is now in a separate task.