Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow a project owner to disable shared workspaces #6328

Open
mikenikles opened this issue Oct 20, 2021 · 7 comments
Open

Allow a project owner to disable shared workspaces #6328

mikenikles opened this issue Oct 20, 2021 · 7 comments
Labels
aspect: security Anything related to preventing vulnerabilities component: dashboard feature: collaboration Features that enable collaboration across a shared workspace (e.g. multi-cursor) feature: policy feature: teams and projects [DEPRECATED] Please, use feature: organizations or feature: projects labels instead. meta: never-stale This issue can never become stale team: webapp Issue belongs to the WebApp team type: feature request New feature or request

Comments

@mikenikles
Copy link
Contributor

Based on feedback we received via the docs feedback widget: "Can we disable sharing globally for teams (as a security measure)?"

@mikenikles mikenikles added type: feature request New feature or request aspect: security Anything related to preventing vulnerabilities 🧑‍🚀 crew: teams and projects feature: teams and projects [DEPRECATED] Please, use feature: organizations or feature: projects labels instead. team: webapp Issue belongs to the WebApp team team: workspace Issue belongs to the Workspace team feature: collaboration Features that enable collaboration across a shared workspace (e.g. multi-cursor) labels Oct 20, 2021
@gtsiolis
Copy link
Contributor

FYI, This is also cross-linked[1] in the docs. 🎗️

@stale
Copy link

stale bot commented Feb 24, 2022

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale bot added the meta: stale This issue/PR is stale and will be closed soon label Feb 24, 2022
@gtsiolis
Copy link
Contributor

Introducing 🅰️ team-level or also 🅱️ instance-level setting sounds interesting. 💭

We also recently disabled snapshots for repositories users don't have access to in #8306.

@stale stale bot removed the meta: stale This issue/PR is stale and will be closed soon label Feb 24, 2022
@reustle
Copy link

reustle commented Apr 28, 2022

Currently the docs say:

Beware, anybody with this URL and a Gitpod account will be able to access the workspace as long as it is shared and running.

Would it be technically feasible with the existing GitHub API to for example, allow anyone with a GitPod account that is linked to a GitHub account which has access to this repo to access the workspace? Thank you.

@geropl geropl removed the team: workspace Issue belongs to the Workspace team label Apr 29, 2022
@joeizy
Copy link

joeizy commented Jun 24, 2022

GitHub organization could be a good security boundary to allow/deny. Not sure if other platforms (i.e. GitLab, etc.) have a similar construct.

@stale
Copy link

stale bot commented Oct 19, 2022

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale bot added the meta: stale This issue/PR is stale and will be closed soon label Oct 19, 2022
@gtsiolis gtsiolis added meta: never-stale This issue can never become stale and removed meta: stale This issue/PR is stale and will be closed soon labels Oct 19, 2022
@andreas-vogl
Copy link

+1 for instance and team level setting to deactivate workspace sharing.

From the docs it seems you are well aware of the risks. I see this as a blocker for a wider rollout, as sharing a workspace like this equals leaking SCM credentials.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
aspect: security Anything related to preventing vulnerabilities component: dashboard feature: collaboration Features that enable collaboration across a shared workspace (e.g. multi-cursor) feature: policy feature: teams and projects [DEPRECATED] Please, use feature: organizations or feature: projects labels instead. meta: never-stale This issue can never become stale team: webapp Issue belongs to the WebApp team type: feature request New feature or request
Projects
Status: No status
Development

No branches or pull requests

7 participants