Skip to content

Default application binding #3732

@DrMurx

Description

@DrMurx

The documentation reads:

By default, all users can access applications when no policies are bound.

This feels against all security best practices, as default settings should be as limited as possible.

I'd like to propose a "Default Binding" for applications which is always in place for all applications with no custom bindings. This default binding should be set to "Deny all users" policy initially. The administrator might customize it to their taste.

For backwards compatibility, the default binding may be set to an "Allow all users" policy for existing Authentik setups so it doesn't break logins when the administrator upgrades from an Authentik version which doesn't have this feature.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestenhancement/confirmedEnhancements that will be implemented in the future

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions