-
Bug
-
Resolution: Not a Bug
-
Major
-
None
-
2.0 GA, SaaS
-
-
+
-
Admin portal SSO integration allows any user with the login URL to sign in to 3scale via RH SSO without an invitation. This was discovered when using the "Test the authentication flow" feature and it created a user in 3scale as a result.
Additionally this was attempted once the SSO feature was published and again a user was created in 3scale as described above.
Also the fact that the invitation is not needed means that the admin portal is potentially open to buyer accounts being able to sign in via the SSO server. There is no distinction made on the IdP level if the same realm is used and very few API providers will want to manage multiple realms, however, I suspect the fix is just to ensure an admin user can only create the account via the signup link.
- is related to
-
THREESCALE-5787 Document Considerations for using separate realms for admin and developer portal
-
- Defining
-