You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I've just noted that after enabling LDAPAuthenticator.allowed_groups, one user who was not included in the application group was still able to login, probably based on a cookie/browser cache. When the user tried to login from within a private window it didn't succeed, but with a regular browser window login was not required. It seems to be a (minor) security breach.
The text was updated successfully, but these errors were encountered:
Yep - all cookies signed prior to enabling this would probably still be valid. I think rotating the secret key (jupyterhub_cookie_secret file) should fix it.
Thanks for reporting it! I'll add this to the README!
I've just noted that after enabling LDAPAuthenticator.allowed_groups, one user who was not included in the application group was still able to login, probably based on a cookie/browser cache. When the user tried to login from within a private window it didn't succeed, but with a regular browser window login was not required. It seems to be a (minor) security breach.
The text was updated successfully, but these errors were encountered: