-
Notifications
You must be signed in to change notification settings - Fork 2.9k
Closed as not planned
Labels
type: featureIntroduction of new functionality to the applicationIntroduction of new functionality to the application
Description
NetBox version
v3.4.4
Feature type
New functionality
Proposed functionality
Netbox has the ability to use multiple SSO providers, but there is no way to completely disable the login form even if there are no local users on the Netbox instance.
This could pose an unnecessary way for attackers to brute force the application by spamming the login field, especially if the Netbox instance is run in the cloud.
Use case
By adding an option to disable the login form and only having the option to login using an SSO provider would decrease the attack surface for a malicious entity.
Database changes
N/A
External dependencies
N/A
ssza, proudbro, Kerwood, dlorent, OrKarstoft and 8 morejeremystretchKerwood and mewm
Metadata
Metadata
Assignees
Labels
type: featureIntroduction of new functionality to the applicationIntroduction of new functionality to the application
