It's important to be able to limit the login for only those from an organization.

      This eliminates the need of manually disabling accounts of people who doesn't work at the company anymore. If their account is removed from the github org, they can't login to jenkins anymore.

          [JENKINS-51657] limit authentication to github organization

          Agree, current behaviour  is unsecure - every GitHub user can authenticate.

          I suggest to raise priority of this issue.

          Vitaly Karasik added a comment - Agree, current behaviour  is unsecure - every GitHub user can authenticate. I suggest to raise priority of this issue.

          Mark Stosberg added a comment -

          I agree the current default is a major security issue. It's reasonable to expect that logins are restricted to an organization by default. Since anyone can sign up for a free Github account, the current default is essentially to allow public access to Jenkins-- NOT SECURE.

          Mark Stosberg added a comment - I agree the current default is a major security issue. It's reasonable to expect that logins are restricted to an organization by default. Since anyone can sign up for a free Github account, the current default is essentially to allow public access to Jenkins-- NOT SECURE.

          Agree - This should be addressed so that only a specific organization can even login.

          Brandon Shough added a comment - Agree - This should be addressed so that only a specific organization can even login.

          Sam Gleske added a comment -

          Duplicated by JENKINS-46962

          Sam Gleske added a comment - Duplicated by JENKINS-46962

            sag47 Sam Gleske
            samueloph Samuel Henrique
            Votes:
            3 Vote for this issue
            Watchers:
            6 Start watching this issue

              Created:
              Updated:
              Resolved: