CodeTogether-Inc / CodeTogether-Live

Repository for issues, documentation and more for codetogether.com and associated VS Code extension and Eclipse plugins.
Other
103 stars 12 forks source link

Do not allow users to change display names when using SSO #388

Open brianvfernandes opened 2 years ago

brianvfernandes commented 2 years ago

When authenticated with SSO, you can change your display name to whatever you choose. This could be a security hazard as someone could use this ability to hide or misrepresent their identity.

Alternatively, if the display is changed, the authorization request could show their ‘real’ SSO identity in brackets.