Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Using SSO to sign up for an account bypasses some of the information that needs to be filled out #16256

Open
matrixbot opened this issue Dec 21, 2023 · 0 comments

Comments

@matrixbot
Copy link
Collaborator

matrixbot commented Dec 21, 2023

This issue has been migrated from #16256.


Description

For example, assuming that the server is set up to require an email address to register in order to avoid spam as much as possible, when I use GitHub OAuth for authorization to sign up for an account, I can sign up for an account without filling in my email address.

Steps to reproduce

  • Set Synapse to have to verify email address to register
  • Setting up to allow third-party authorization registration, such as GitHub OAuth
  • Sign up for an account using GitHub OAuth without verifying your email address

Homeserver

Matrix.org can reproduce this situation

Synapse Version

Synapse 1.91.1

Installation Method

Debian packages from packages.matrix.org

Database

IDK

Workers

I don't know

Platform

Matrix.org

Configuration

IDK

Relevant log output

IDK

Anything else that would be useful to know?

No response

@matrixbot matrixbot changed the title Dummy issue Using SSO to sign up for an account bypasses some of the information that needs to be filled out Dec 22, 2023
@matrixbot matrixbot reopened this Dec 22, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant