soudis / discoursesso

Nextcloud App providing Discourse SSO
GNU Affero General Public License v3.0
15 stars 5 forks source link

Nextcloud - Prevent from having multiple user with the same email. #26

Open warnerbryce opened 2 years ago

warnerbryce commented 2 years ago

Hello,

@soudis You said several times in your documentation : "There is a security vulnerability if you allow for multiple user accounts with the same e-mail address in nextcloud"
I understand why, but i can't find a way to prevent this into my Nextcloud instance (i am the admin).

By default i can put the same address email to several users. I can't find on internet and documentation how can i block this beahaviour in Nextcloud ?

Does the admin have to be carefull when creating users ? Of a config.php line have to be written to automatically block it ?

Thank you.

satonotdead commented 1 year ago

Did you figured it out?

soudis commented 1 year ago

Unfortunately, I'm not using the nextcloud user management but I use an LDAP server with a custom management tool. Therefore I don't really know if there is a way to prevent duplicate email addresses