Summary
When I create an account through SSO, users aren't given (and don't need) a password. But then any action that requires a sudo prompt is impossible to complete. This is especially a problem when instances want an external IdP to manage all user accounts and set SSO to required. A solution would be to give the sudo prompt the ability to redirect to SSO for an authentication check when an SSO connection is set on the current user. However when it comes to the security methods in specific there's also the question of whether they should even be available to accounts provisioned by SSO in the first place, since that stuff should probably be the responsibility of the user's connected IdP. I made a separate issue for that. #702 Current workaround: Setup a password on the account first. Although I think it's not quite desired to need a password in an SSO provisioned account in order to do actions such as deleting a server. SSO's main purpose is to take away the need to have passwords and logins on each service.Steps to reproduce
- Set up a Fluxer instance.
- Enable SSO login.
- Create an account through the SSO flow.
- Login and go to Account settings.
- Try to add a Passkey, Authenticator app, delete a server or trigger any other action that requires a sudo prompt.
- Get stuck on the "Verify it's you" prompt.
Comments
No comments yet.