Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

request: page note reminding people that 'login with email' might be what they want to see *all* signed in sites #343

Open
gregglind opened this issue Oct 6, 2018 · 6 comments

Comments

@gregglind
Copy link

Hello firends: I was able to reproduce my SSO issue:

  • autologin with LDAP => full list of sites with moz logins.
  • using the ‘login with google’ button => just a handful (9 Mozilla maintained sites = airmo, mdn, treeherder… events)

The solution of always login with email is correct.

Maybe we can put a note suggesting that solution in the dashboard?

@hmitsch
Copy link
Contributor

hmitsch commented Oct 8, 2018

@gdestuynder @andrewkrug can you please take a look at this? This is a staff member who is able to select "login with Google". Shoudn't account ratcheting kick in here?

Best regards,
Henrik

@gdestuynder
Copy link
Contributor

There's no ratcheting at the moment for Google accounts backed by LDAP
This is mainly because some people already have accounts between the 2. Both use the same authentication and are +- as safe to use.

We've a feature item that removes this, though it requires a lot of comm to resolve accounts on the RP side so that there is no orphaned/unreachable accounts

Note: not all users want "login with email", mostly staff users and passwordless users want this, and others dont

@gregglind
Copy link
Author

gregglind commented Oct 8, 2018 via email

@andrewkrug
Copy link
Contributor

@gregglind the email field is for non staff though. It's also used by volunteers, NDA volunteers, pocket and mozilla foundation employees.

@andrewkrug
Copy link
Contributor

Dashboard: a note saying "staff: looking for something else? Logout and login with email instead."

The sso-dashboard grid of apps is generated based on your group membership. Logging out and logging in with e-mail results in fewer available services not more.

@gregglind
Copy link
Author

gregglind commented Oct 8, 2018 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants