-
-
Notifications
You must be signed in to change notification settings - Fork 1.5k
Closed
Labels
enhancementNew feature or requestNew feature or requestenhancement/confirmedEnhancements that will be implemented in the futureEnhancements that will be implemented in the future
Milestone
Description
The documentation reads:
By default, all users can access applications when no policies are bound.
This feels against all security best practices, as default settings should be as limited as possible.
I'd like to propose a "Default Binding" for applications which is always in place for all applications with no custom bindings. This default binding should be set to "Deny all users" policy initially. The administrator might customize it to their taste.
For backwards compatibility, the default binding may be set to an "Allow all users" policy for existing Authentik setups so it doesn't break logins when the administrator upgrades from an Authentik version which doesn't have this feature.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requestenhancement/confirmedEnhancements that will be implemented in the futureEnhancements that will be implemented in the future