Skip to content

Comments

chore: let abandoned SSO users recover their accounts#12646

Draft
Dschoordsch wants to merge 1 commit intomasterfrom
chore/accountRecoveryAfterLosingSSO
Draft

chore: let abandoned SSO users recover their accounts#12646
Dschoordsch wants to merge 1 commit intomasterfrom
chore/accountRecoveryAfterLosingSSO

Conversation

@Dschoordsch
Copy link
Contributor

When a user was created via SSO but now that SSO is not set up anymore, they lose access to their accounts.
Just removing SAML from an organization is not the same as a data deletion request and should also not be treated as a way to lock out users, so let those users recover their accounts by signing up a different way.

Description

Fixes/Partially Fixes #[issue number]
[Please include a summary of the changes and the related issue]

Demo

[If possible, please include a screenshot or gif/video, it'll make it easier for reviewers to understand the scope of the changes and how the change is supposed to work. If you're introducing something new or changing the existing patterns, please share a Loom and explain what decisions you've made and under what circumstances]

Testing scenarios

[Please list all the testing scenarios a reviewer has to check before approving the PR]

  • Scenario A

    • Step 1
    • Step 2...
  • Scenario B

    • Step 1
    • Step 2....

Final checklist

  • I checked the code review guidelines
  • I have added Metrics Representative as reviewer(s) if my PR invovles metrics/data/analytics related changes
  • I have performed a self-review of my code, the same way I'd do it for any other team member
  • I have tested all cases I listed in the testing scenarios and I haven't found any issues or regressions
  • Whenever I took a non-obvious choice I added a comment explaining why I did it this way
  • I added the label Skip Maintainer Review Indicating the PR only requires reviewer review and can be merged right after it's approved if the PR introduces only minor changes, does not contain any architectural changes or does not introduce any new patterns and I think one review is sufficient'
  • PR title is human readable and could be used in changelog

When a user was created via SSO but now that SSO is not set up anymore,
they lose access to their accounts.
Just removing SAML from an organization is not the same as a data
deletion request and should also not be treated as a way to lock out
users, so let those users recover their accounts by signing up a
different way.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant