#3686 - More configurability of IP address session locking

Identifier #3686
Issue type Feature request or suggestion
Title More configurability of IP address session locking
Status Closed (rejected)
Tags

Roadmap: v11 (custom)

Handling member Chris Graham
Addon core
Description Rather than having a global option about how sessions are restricted to IP address, make it configurable based on usergroup.

Possibilities (in decreasing order of security):
1) Check full IP
2) Check without last octet
3) Check same subnet
4) No check

A session would be restricted based on the highest security usergroup of the user behind that session.
Steps to reproduce

Additional information The problem is some users may be on CGNAT, or TOR, and have wild IP addresses. My view is that we can accept this for non-admins, but for admins we should by default give them extra security (which isn't perfect, but something).

Twitter thread: https://twitter.com/occhris/status/1042493166425960448
Funded? No
The system will post a comment when this issue is modified (e.g., status changes). To be notified of this, click "Enable comment notifications".

Rating

Unrated