Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Eh, that’s a matter of opinion on policy. Technically (at least with Slack) it is possible to require SSO for users and control over which profile attributes they can change themselves, including display name. Although they may get clobbered at login as part of reading the SAML doc.


Just because you can, doesn’t mean you should - and in fact is a security hole if you do. We don’t allow security holes where I work so all attributes are copied over and nothing can be changed. No hidden employees. No unknown guests.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: