Option to Restrict Primary Domain #1209

Closed
opened 2026-04-05 18:31:43 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @jflattery on 7/19/2025

In Pangolin, the primary domain appears to be usable by all organizations by default, which can cause access conflicts or security concerns in multi-organization setups. For instance, in environments with multiple organizations managing their own sites and resources, admins need a way to prevent automatic access to the primary domain to enforce stricter controls.

Introduce a configuration option to restrict the primary domain from default usage by organizations. Once restricted, allow admins to explicitly assign the primary domain to specific organizations (e.g., via the admin interface for managing organizations, sites, users, and roles). This could include:

  • A global setting toggle (e.g., "Restrict primary domain to assigned organizations only").
  • An assignment mechanism in the UI, where the primary domain can be linked to selected organizations, integrating with existing role-based access control (RBAC) for resources.
*Originally created by @jflattery on 7/19/2025* In Pangolin, the primary domain appears to be usable by all organizations by default, which can cause access conflicts or security concerns in multi-organization setups. For instance, in environments with multiple organizations managing their own sites and resources, admins need a way to prevent automatic access to the primary domain to enforce stricter controls. Introduce a configuration option to **restrict the primary domain from default usage by organizations**. Once restricted, allow admins to **explicitly assign the primary domain to specific organizations** (e.g., via the admin interface for managing organizations, sites, users, and roles). This could include: - A global setting toggle (e.g., "Restrict primary domain to assigned organizations only"). - An assignment mechanism in the UI, where the primary domain can be linked to selected organizations, integrating with existing role-based access control (RBAC) for resources.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/pangolin#1209