-
-
Notifications
You must be signed in to change notification settings - Fork 1.5k
Open
Labels
Milestone
Description
Describe the bug
If an administrator connected as akadmin follows an invitation link in the same browser window, the akadmin account will be overwritten by the username seted within the invitation.
To Reproduce
Steps to reproduce the behavior:
- Connect to Authentik as akadmin
- Create an invitation
- Open the invitation in the same browser window that the akadmin connection
- Follow the enrollment process
Expected behavior
The akadmin user should be protected to not be broken accidentally.
For example if we open the invitation link in the bad browser:
- solution 1:
- to disconnect the akadmin user
- to create the new user
- solution 2:
- to display an error message to inform that you are connected as akadmin and then you are unable to continue the invitation process
Version and Deployment (please complete the following information):
- authentik version: 2025.8.1
- Deployment: docker-compose
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Type
Projects
Status
Todo