apache / apache/superset

LDAP/OAuth authentication should NOT enable public/open registration via UI by default

Open
#37,100 3 comments 3 reactions 1 assignee Claimed by @dpgaspar View on GitHub
authentication 🦾 ai-candidate
Dominant language
Python
Stars
74.8k
Forks
18.3k
Avg merge
2d 4h
Merged PRs (30d)
664

Description

### Bug description

For LDAP/OAuth authentication to work, AUTH_USER_REGISTRATION must be set to True (in superset_config.py) in order to allow syncing of Superset DB with LDAP/OAuth provider.

However, 'AUTH_USER_REGISTRATION = True' also enables registration path on Superset UI (registration button,etc.). This is a potential security hole, and there are numerous use cases where this is HIGHLY undesirable.

Open/public registration should be optional and disabled by default for any type of authentication, including LDAP/OAuth.

### Screenshots/recordings

_No response_

### Superset version

master / latest-dev

### Python version

3.9

### Node version

16

### Browser

Chrome

### Additional context

_No response_

### Checklist

- [ ] I have searched Superset docs and Slack and didn't find a solution to my problem.
- [ ] I have searched the GitHub issue tracker and didn't find a similar bug report.
- [ ] I have checked Superset's logs for errors and if I found a relevant Python stacktrace, I included it here as text in the "additional context" section.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.