•  
      request #10193 Possibility to disable "New User" on home page
    Infos
    #10193
    Jean-Louis Schricke (mesulog)
    2017-10-26 20:03
    2017-04-29 16:33
    10462
    Details
    Possibility to disable "New User" on home page
    Home page is accessible to anybody.
    We receive a lot of requests for user creation from people who will never be approved.
    Since the decision of user creation for one of our customers belongs to us, we would like to be able to disable the link to /account/register.php in navbar.
    To day, we have to edit theme Template to do that.
    Other
    All
    Empty
    • [x] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Empty
    New
    Empty
    Attachments
    References
    Referencing request #10193

    Follow-ups

    User avatar
    Manuel,

    This evening I updated my Tuleap to stable 9.13 and added the captcha plugin.
    After configuring it, I now get the "I am not a robot" in the footer of the user creation page.

    Thank you.
    Hoping it will stop the creation of undesired users.
    User avatar

    Rule n°1 of captacha plugin club, if you cannot find it, you don't deserve it.

    But you can be member of the club with a local install of the rpm with "yum" then it will be in available plugin in site admin interface.

    Pretty much like 100% of other plugins on Tuleap

    User avatar
    last edited by: Jean-Louis Schricke (mesulog) 2017-10-25 14:26
    Thank you Manuel for your answer.
    I am interested to activate the Captcha plugin but I didn't find how to do it.
    This plugin is not installed and do not appear as available plugin in "Administration + Plugins"
    Could you give me any additional link to Captcha plugin in Tuleap documentation ?
    User avatar

    Jean-Louis, we really appriciate the effort you are putting in turning this into a troll.

    Please consider securing your installation first as it's done on all professionnal deployment of Tuleap, like:

    • enable the captcha plugin.
    • use ldap authentication with an external source of truth for accounts.
    User avatar
    Recently the security has been improved in Tuleap, by exemple it is no more possible to display a PDF file without downloading it.

    Don't you think there is a security failure since anybody can ask for account creation, promoting Viagra or any illegal substances (see user creation détails) ?

    User avatar
    I need to increase severity on this request since release 9.11 adds user creation on login page.

    When using Tuleap for professionnal use, sharing project with customers, we need to control the access and not allow anybody, including robots to create users. Even if user creation has to be approved, Tuleap administrator has other tasks to do than delete fake users.