[GH-ISSUE #725] [Feature Request] Additional User Controls #3535

Closed
opened 2026-04-20 07:31:34 -05:00 by GiteaMirror · 2 comments
Owner

Originally created by @skycorrigan on GitHub (May 14, 2025).
Original GitHub issue: https://github.com/fosrl/pangolin/issues/725

Hello again. After submitting the access log suggestion, I started thinking about some other additions for Pangolin.
Here's a few:

  1. Authorization time limit: Have a setting where users must re-auth after a certain number of hours/days/months or never at all. This would be great for security in the event a user's credentials and/or session were stolen or hijacked. With that, an option to bump sessions would be great for admins if we noticed malicious behavior (this would go in-hand with my suggestion of an access log).

  2. Account disable/re-enable/ban: Another security addition and would go in hand with suggestion #1.

That's all for now. Thank you again.

Originally created by @skycorrigan on GitHub (May 14, 2025). Original GitHub issue: https://github.com/fosrl/pangolin/issues/725 Hello again. After submitting the access log suggestion, I started thinking about some other additions for Pangolin. Here's a few: 1) Authorization time limit: Have a setting where users must re-auth after a certain number of hours/days/months or never at all. This would be great for security in the event a user's credentials and/or session were stolen or hijacked. With that, an option to bump sessions would be great for admins if we noticed malicious behavior (this would go in-hand with my suggestion of an access log). 2) Account disable/re-enable/ban: Another security addition and would go in hand with suggestion #1. That's all for now. Thank you again.
Author
Owner

@oschwartz10612 commented on GitHub (May 14, 2025):

Hi! Thanks for the suggestions again!

I think number one might have already been suggested in https://github.com/orgs/fosrl/discussions/480 and https://github.com/orgs/fosrl/discussions/365.

Number 2 for enabling and disabling users is a good idea so you dont have to delete their whole account! Just to keep things clean would you mind closing this pull request and opening a discussion feature request for that feature?

<!-- gh-comment-id:2880801831 --> @oschwartz10612 commented on GitHub (May 14, 2025): Hi! Thanks for the suggestions again! I think number one might have already been suggested in https://github.com/orgs/fosrl/discussions/480 and https://github.com/orgs/fosrl/discussions/365. Number 2 for enabling and disabling users is a good idea so you dont have to delete their whole account! Just to keep things clean would you mind closing this pull request and opening a discussion feature request for that feature?
Author
Owner

@skycorrigan commented on GitHub (May 14, 2025):

My fault. I overlooked the discussion tab. Will close this out now.

<!-- gh-comment-id:2881323008 --> @skycorrigan commented on GitHub (May 14, 2025): My fault. I overlooked the discussion tab. Will close this out now.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/pangolin#3535