Hacker News new | ask | show | jobs
by scarmig 1121 days ago
They could make the default such that you couldn't grant anyone outside your organization any particular role, unless principals associated with that domain are explicitly whitelisted (by domain).

(And, in the other direction, there should be a request/response flow when you're added to some random project/org you have no interest in, which can make you vulnerable both to legal attacks by the org mistakenly adding you and to phishing.)

1 comments

Many folks have contract admins, it would add a lot of friction for the normal case just to try to prevent something that should be transparently dumb anyway.