Figure out how to have SSO only give basic forgejo permissions #28

Closed
opened 2024-04-29 22:11:07 +00:00 by ktemkin · 3 comments
Owner
No description provided.
ktemkin added this to the Soft Launch project 2024-04-29 22:11:07 +00:00
Owner

we have this already right? the sso currently only gives triage permissions to a group which we have simply assigned everyone in beta to

we have this already right? the sso currently only gives triage permissions to a group which we have simply assigned everyone in beta to
Author
Owner

Ah, I phrased this badly.

This was supposed to be an epic for making sure SSO doesn't do other things for generic GH logged-in users -- e.g. making sure our various services don't incorrectly treat "got a login token" as letting people e.g. see some of the SSO-gated webpages.

This wasn't "do this on forgejo"; this was "make sure nothing else is configured wrong".

Ah, I phrased this badly. This was supposed to be an epic for making sure SSO doesn't do _other_ things for generic GH logged-in users -- e.g. making sure our various services don't incorrectly treat "got a login token" as letting people e.g. see some of the SSO-gated webpages. This wasn't "do this on forgejo"; this was "make sure nothing else is configured wrong".
Author
Owner

Closing this as auditing is now in a separate task.

Closing this as auditing is now in a separate task.
Sign in to join this conversation.
No labels
A-infra
A-matrix
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: lix-project/meta#28
No description provided.