You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I'm not sure how easy this would be (or worthwhile), but was wondering whether we should allowlist the Github usernames that we hand out SSH keys for via this proxy - this would add an extra layer of safeguarding in case of incorrect usernames.
The text was updated successfully, but these errors were encountered:
not a great place to do this, as I think it would be difficult to verify whether the github username is currently a member of the relevant github org (which is potentially the best way to verify whether they currently have access) - but a longer list might help to cut down the possibilities & add to defence in depth.
I'm not sure how easy this would be (or worthwhile), but was wondering whether we should allowlist the Github usernames that we hand out SSH keys for via this proxy - this would add an extra layer of safeguarding in case of incorrect usernames.
The text was updated successfully, but these errors were encountered: