Sitelet https://web.archive.org/web/20200905125019/https://github.com/zulip/zulip/issues/16081
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove Guests option from Invite users dialog when anybody can sign up #16081

Open
Gittenburg opened this issue Aug 9, 2020 · 11 comments · May be fixed by #16135
Open

Remove Guests option from Invite users dialog when anybody can sign up #16081

Gittenburg opened this issue Aug 9, 2020 · 11 comments · May be fixed by #16135

Comments

@Gittenburg
Copy link
Collaborator

@Gittenburg Gittenburg commented Aug 9, 2020 •

If anybody can sign up (i.e. no invitations are required), it doesn't make sense that users can invite other people as "guests" that have fewer permissions than they could get by signing up themselves.

The invite user dialog is currently being worked on (#16077), so there may be some small git conflicts if you work on this now.

@zulipbot
Copy link
Member

@zulipbot zulipbot commented Aug 9, 2020

Hello @zulip/server-settings members, this issue was labeled with the "area: settings UI" label, so you may want to check it out!

@timabbott
Copy link
Member

@timabbott timabbott commented Aug 10, 2020

Hmm, we need to be thoughtful, because one could be trying to use a limited set of enabled authentication backends (E.g. SAML auth with some system) that limits the ability of folks to create accounts, but I'm not sure I see a non-brittle way one could setup authentication such that this would be useful.

I suppose if the URL for your Zulip server is secret, there could maybe be a use case for the option?

@Gittenburg
Copy link
Collaborator Author

@Gittenburg Gittenburg commented Aug 10, 2020 •

limited set of enabled authentication backends (E.g. SAML auth with some system) that limits the ability of folks to create accounts

Good point!

I suppose if the URL for your Zulip server is secret, there could maybe be a use case for the option?

If you invite a user they get the URL in the email, so I think they could still find the sign up page.

PawBud added a commit to PawBud/zulip that referenced this issue Aug 17, 2020
This commit removes the invite users as guest from the dropdown menu from
the invite users dialog. Users who wish to register as guests can hereby
do so from the zulip signup page.
Fixes zulip#16081.
@PawBud
Copy link
Collaborator

@PawBud PawBud commented Aug 24, 2020

@Gittenburg just curious, Am I missing something?

@Gittenburg
Copy link
Collaborator Author

@Gittenburg Gittenburg commented Aug 24, 2020

I guess we shouldn't completely remove the guest option because that effectively renders the guests feature useless. We should only remove it if sign up is unrestricted, i.e. no invitations are required to sign up and sign up is not restricted to specific email domains. If we should also account for restricting to certain auth backends, depends on if such a restriction can be set up reliably (which I don't know, @timabbott suggested it might not be currently possible).

@PawBud
Copy link
Collaborator

@PawBud PawBud commented Aug 24, 2020

So, should I close my PR?

@Gittenburg
Copy link
Collaborator Author

@Gittenburg Gittenburg commented Aug 24, 2020 •

I think it is only lacking a more elaborate if condition (the template should just check a boolean like guests_enabled that is set in zerver.views.home.home_real). The difficulty is mainly in working out when we want to enable / disable guest invites, for example:

  • realm.invite_required -> guests_enabled = True
  • zproject.backends.any_social_backend_enabled -> guests_enabled = False
@PawBud
Copy link
Collaborator

@PawBud PawBud commented Aug 24, 2020 •

I think it is only lacking a more elaborate if condition (the template should just check a boolean like guests_enabled that is set in zerver.views.home.home_real). The difficulty is mainly in working out when we want to enable / disable guest invites, for example:

  • realm.invite_required -> guests_enabled = True
  • zproject.backends.any_social_backend_enabled -> guests_enabled = False

I see, well I haven't really checked out zulip's backend, This should be a good opportunity to tinker around :)

@PawBud
Copy link
Collaborator

@PawBud PawBud commented Aug 31, 2020

ok, I think I am confused now, as to what are we trying to achieve here, I thought we were ok with completely removing the guest option? Or at least let's keep it for non-members(Org admins, owners) but then that wouldn't make sense, Moreover u said that users can still sign up as guests through the sign-up page, so we are technically not removing the option overall?

@Gittenburg
Copy link
Collaborator Author

@Gittenburg Gittenburg commented Aug 31, 2020

Through the sign-up page you sign up as a full user (not as a guest). So offering the guest option doesn't make sense when anybody can just get a full account by signing up for a new account.

@PawBud
Copy link
Collaborator

@PawBud PawBud commented Sep 1, 2020 •

I see, so if we have to remove it overall, This should require a discussion at length with others, right?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

4 participants
You can’t perform that action at this time.