Open sapielsam opened 9 months ago
Based on the problem described in the article
Steps to reproduce the problem:
The actual result: A new account with username: firstname.lastname+hacker@domain.org is created and given default permissions.
Is it possible to add a check for jwt claim hd or via getHostedDomain to check if the user belongs to an organization?
I think the problem here
Based on the problem described in the article
Steps to reproduce the problem:
The actual result: A new account with username: firstname.lastname+hacker@domain.org is created and given default permissions.
Is it possible to add a check for jwt claim hd or via getHostedDomain to check if the user belongs to an organization?