Discourse Meta
Security/Privacy concern: Email exposed in DiscourseConnect Provider redirect URL
Contribute
Feature
pr-welcome
Falco
(Falco)
March 9, 2026, 6:10pm
2
Isn’t that also encrypted with the shared secret?
1 Like
show post in topic
Related topics
Topic
Replies
Views
Activity
Setup DiscourseConnect - Official Single-Sign-On for Discourse (sso)
Integrations
sso
,
configuring
,
discourseconnect
,
how-to
45
453728
January 28, 2026
Use Discourse as an identity provider (SSO, DiscourseConnect)
Integrations
sso
,
discourseconnect
,
how-to
143
49891
November 9, 2024
DiscourseConnect / SSO. Force users to provide an email after redirecting from the parent website
SSO
discourseconnect
,
email
0
301
September 13, 2022
Create a DiscourseConnect login link
Integrations
sso
,
discourseconnect
,
how-to
6
6258
September 25, 2024
Integration into custom auth system where emails are not unique?
SSO
email
40
1304
June 6, 2024