Allow me to signup without GitHub/BitBucket and clarify what CircleCI really have access to
complete
T
Tore
Yes, the automatic signup with GitHub is convenient to CircleCI, but my security conscious starts to feel unease and I feel very unsure about what access CirculeCI really have. Does circleCI now have direct access to all my GitHub repos?What if I don't want CircleCI to have a default access to all my repositories?
I wished i could signup as a normal user, and then manually add and give access to individual repositories, so I can feel more confident that circleCI only can see the repositories that it should see and nothing else.
Basically, I want to apply the law of least privilege here.
CCI-I-791
S
Spencer Franks
complete
S
Spencer Franks
Hello! With the release of our new GitHub App (https://discuss.circleci.com/t/announcing-a-more-secure-team-member-signup-experience/49007), you can now select which GitHub repositories CircleCI has access to.
Couple of notes:
- You will need to create a new organization in order to use this.
- This is not available for BitBucket.
- There are currently some limitations with this method of connecting compared to the old way (see here: https://circleci.com/docs/github-apps-integration/#currently-not-supported)
Please let me know if you're still interested and have any further feedback!
Thanks!
Spencer
Jake Cozart
Sarah Seaton what happened to this being under review? It has been two years.
Jake Cozart
This request has been out here for two years. I can't believe this has not been completed yet. I know our team has a need for QA to be able to approve steps but we do not want to give them access to git NOR pay for their seats in git. Come on CircleCI. You are REALLY dropping the ball on this one.
r
roger thomas
Just to bump this up the list a little as the issue is rather a talking point at this time.
Sarah Seaton
under review
Merged in a post:
Login access by non-bitbucket user
C
Colin Mackie
We have our Bitbucket team linked to our circle account, however, the person who adds payments methods is not a developer so not in that team and cannot access the account.
It would be useful if another user can be added that could access the account for billing and admin purposes. This would just be a traditional email/password login.
CCI-I-862
Merged in a post:
allow users to signup / login using email, password
P
Piyush
This is in relation to my question in forum:https://discuss.circleci.com/t/signup-login-using-email/28982Currently CircleCI requires user to signin via github / bitbucket and asks for read permissions for all the user's account.
It's not like I do not trust CircleCI but I’ve quite a few client project and I'm not authorised to give read access.My clients use their own bitbucket / github accounts, they've setup CircleCI using their account.
I have access to source code as well as CircleCI account using my email.But unfortunately CircleCI needs access to all project which I cannot do (it will be legal offence for me).
I believe this will be applicable to many developers.
So CircleCI team, can you please allow users to signup / login using email/password only?If not, can you please allow users to log in at the minimum? (Let the Owner/Admin of CircleCI for respective account set the password for other users.)
Thanks
CCI-I-948
A
Arthur Kepler
Yes, this is dangerous and insecure by design. Seems like it provides an irresponsible level of liability for CircleCI too.
R
R Kraan
Hi
I need a login to Circle as an addition to the GitHub and BitBucket users.
At github we must pay for extra users if we want to give them view acces howeverd view access on github is not secure enough. We need to setup acounts and right directly in Circle as extra on the users from Github.
Second the administration and finance need to access the acount. These people are not on github as they are not part of the development team.
So please consider to make extra accounts available.
Thanks
Load More
→