galaxyproject / galaxy

Data intensive science for everyone.
https://galaxyproject.org
Other
1.42k stars 1.01k forks source link

Preserve a list of permanently banned email addresses to prevent abuse via reusing after account is purged #19095

Open jdavcs opened 1 month ago

jdavcs commented 1 month ago

Based on a recent discussion on galaxyadmin slack: it would be nice to have a way to permanently ban users and save the banned email addresses to prevent them from being reused for registering new accounts after the banned accounts have been purged.

This could be a per-galaxy list or one optionally-available master list, or both. It can be implemented as a database table (then we can store additional relevant information (banned when and why), or as a simple text file (we can hash the email addresses so they are not made public).

@natefoo @jennaj

ElectronicBlueberry commented 1 month ago

just as a note: let's not forget plus addressing if we implement something like this

natefoo commented 1 month ago

Gmail dots as well, but hopefully there aren't a million special cases like Gmail.