Hacker News new | ask | show | jobs
by askvictor 1178 days ago
SSO idp would generally pass an email address through to the service, no? I could be mistaken about that, but if so, then you'd still have access to a password-recovery-by-email if the identity provider shuts down.
1 comments

I've seen many systems that disallow the password reset flow when you sign in via SSO, since the expectation is that you as the service provider are not the authority for the user's identity.
Can confirm, happened to me just yesterday for ngrok.com/Login with Google.