[Self-Hosted] SSO provisioned users can do actions they shouldn't

(#702) Bug Needs triage security self-hosting

Thread

Comment by @thefathacker
RexSystem 1 vote edited originally by @thefathacker on GitHub
I would almost make it an option to have this level of enforcement, I agree that #696 is an issue. But the lockdown to not allow changes be be wanted for a locked down or corporate setting. but not if you are operating it in a social one.