Block a user
Change LDAP directory structure to accommodate multiple domains
Thanks for clarifying it, this is all clearer to me now
LDAP users should only be able to change their own password
Yes, there are ACIs for everything. We can create an account for akkounts-api that can create users and nothing else
Change LDAP directory structure to accommodate multiple domains
OK, now I understand. In Gitea there is a global setting for "Allow Creation of Organizations by Default", that is off by default and off in our deployment. Admins can always create organizations, and there's also a flag on regular users for their ability to create organizations if needed
Change LDAP directory structure to accommodate multiple domains
So far I think for the use case of enabling different services, that roles, in particular filtered roles would be a good fit.
Cap amount of users/accounts
This is a good idea, I think we should keep this around and revisit it before we go public!
LDAP users should not be able to list other users' email address
Add usage instructions for ipfs-cluster