Skip to content

Docs: describe open-source authentication and access accurately - #16166

Merged
devGregA merged 1 commit into
DefectDojo:bugfixfrom
devGregA:devgrega/oss-auth-copy-accuracy
Oct 2, 2026
Merged

devGregA merged 1 commit into
DefectDojo:bugfixfrom
devGregA:devgrega/oss-auth-copy-accuracy

Conversation

@devGregA

@devGregA devGregA commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Description

Since 3.0, open-source DefectDojo has local accounts plus per-Asset and per-Organization Authorized Users lists. It has no roles, groups, global roles, SSO, LDAP or MFA. Several public surfaces still said otherwise:

  • README.md listed "OAuth2/SAML2" and "LDAP" as authentication options. Both links now redirect to the archived-docs index and the Pro LDAP page. Replaced with one line stating what each edition supports, linking to the SSO section.
  • Editions table (get_started/about/defectdojo_versions) said open source has "basic RBAC". It now says "Local accounts and per-Asset access lists", and the Pro column lists SSO (SAML, OIDC, OAuth), LDAP, MFA and role-based access control.
  • Open-source pages (creating users, new-user checklist, Assets, Organizations, Environments, Regulations) referred to global roles and RBAC, or linked to the Pro permission pages. They now link to Open-Source Permissions.
  • Translations of these pages in all seven languages are updated to match. They had also kept an MFA setup step and an MFA recovery section that the English page no longer has. Both are removed.
  • readme-docs/AVAILABLE-PLUGINS.md is removed. Nothing links to it, and it listed SAML, LDAP and MFA plugins as if they were available.

No behavior changes.

Checklist

  • Docs only, so it targets bugfix.
  • New link targets checked on the live site (200).

🤖 Generated with Claude Code

Open-source DefectDojo 3.x has local accounts and per-Asset /
per-Organization Authorized Users lists, with no roles, groups, global
roles, SSO, LDAP or MFA. Several open-source pages and the README still
described those features or linked open-source readers to Pro
permission pages.

- README: replace the OAuth2/SAML2 and LDAP links (both now redirect to
  archived or Pro pages) with a plain statement of what each edition
  supports.
- Editions table: "basic RBAC" becomes "per-Asset access lists"; the Pro
  column lists SSO, LDAP, MFA and role-based access control.
- Open-source user, asset, organization, environment and regulation
  pages: point to the Open-Source Permissions page instead of Pro role
  pages, drop "global role" references, and remove the MFA steps and MFA
  recovery section that remained in the translations.
- Remove readme-docs/AVAILABLE-PLUGINS.md (unreferenced, listed SAML,
  LDAP and MFA plugins).

All seven translations updated to match.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@devGregA
devGregA added this pull request to the merge queue Oct 2, 2026
Merged via the queue into DefectDojo:bugfix with commit 1e6ca33 Oct 2, 2026
48 checks passed
@devGregA
devGregA deleted the devgrega/oss-auth-copy-accuracy branch October 2, 2026 22:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants