Feature Request: Deny users?
-
First of all, thanks for a rock-solid plugin! It’s very clean, simple, and works great for network sites.
Second, I’d like to make a feature request. While automatic user creation is awesome for sites that need it, I don’t like the prospect of letting unauthorized users sign in to my sites, even if it just creates a subscriber account. This is for use in education, so the only users I want being able to log in are those instructors or students who I’ve explicitly added.
You already have a checkbox for whether or not SSO logins will be synchronized with existing accounts. What about making another checkbox to also deny automatic account creation? I think a good implementation might be to let the user authenticate with their SSO credentials, but then show them a (customizable?) message that lets them know they’re not allowed to login to the backend. Then they could be automatically redirected to the front page (or some other customizable location).
The above suggestion assumes that no group membership information is being provided with the SSO session. Of course, if there is group membership info, we’d want to streamline things by allowing automatic account creation. But what about users who shouldn’t have access based on their group (i.e. site is public, but login is restricted to faculty, so students should be denied login)? I’d still like to see them denied login access and redirected to the front page. Maybe a better function for the checkbox would be “Deny automatic creation of unauthorized users.”
This is certainly not a requirement of this plugin, but from a user management standpoint, it’s gravy.
Thanks again!
The topic ‘Feature Request: Deny users?’ is closed to new replies.