8000 Registration Token requirement can be bypassed by logging in with SSO · Issue #11067 · matrix-org/synapse · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
This repository was archived by the owner on Apr 26, 2024. It is now read-only.
This repository was archived by the owner on Apr 26, 2024. It is now read-only.
Registration Token requirement can be bypassed by logging in with SSO #11067
Open
@morg-mov

Description

@morg-mov

Description

Registration Token requirement (where you need a token given by an admin to sign up) can be bypassed by using a Third Party (OpenID) login service
I wish to have OpenID enabled on my private homeserver for the convenience of the people I give access to.
And I have registration tokens enabled since my Homeserver is private. (duh)

Steps to reproduce

  • Create account via Third Party (Twitch, Google, Github, Whatever) with Registration Token requirement enabled.

Version information

  • Homeserver: Would rather not provide publicly due to it being private, however it is self-hosted.

If not matrix.org:

  • Version: 1.44.0

  • Install method: Docker-Compose

  • Platform: Ubuntu 20.04 Server running on actual hardware, Homeserver running in Docker Container

Metadata

Metadata

Assignees

No one assigned

    Labels

    A-RegistrationCreating an accountA-SSOSingle Sign-On (maybe OIDC)A-Social LoginLogin via external identity providersP4(OBSOLETE: use S- labels.) Okay backlog: will not schedule, will accept patchesT-EnhancementNew features, changes in functionality, improvements in performance, or user-facing enhancements.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      0