-
Bug
-
Resolution: Fixed
-
Blocker
-
3.7.4, 3.8.1, 3.9, 3.9.10, 3.10.7, 3.11.3, 3.11.5
-
MOODLE_310_STABLE, MOODLE_311_STABLE, MOODLE_37_STABLE, MOODLE_38_STABLE, MOODLE_39_STABLE
-
MOODLE_311_STABLE
-
master_
MDL-67802_2 -
-
1
Commit df6092d65c21dbb54dc76703af98652ccef0c37c (MDL-66598?) reads
Only Facebook, Google, and Microsoft issuers can optionally offer to
|
require account confirmation via email. We will require email
|
confirmation for the rest of the issuers. |
Seriously? Are these three the only trustworthy OAuth providers in the world? Have sysadmins really become this dumb that you need to hard-code the words "Google", "Facebook" and "Microsoft" for security reasons? This commit effectively makes it impossible for my organization to use the module to login with an internal provider.
- has a non-specific relationship to
-
MDL-76380 Unable to edit OAuth2 Service if requireconfirmation is disabled
-
- Closed
-
- is a clone of
-
MDL-67556 Oauth2 : "Require email verification" is hardcoded to true for custom issuers.
-
- Closed
-
- is duplicated by
-
MDL-68389 Missing checkbox for "Require email validation"
-
- Closed
-