You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
v2.14.3: account bindings surface in multi-account detail
- The multi-account drill-down now lists every third-party identity behind each
account — the built-in ones (email, GitHub, Discord, OIDC, WeChat, Telegram,
LinuxDO, Steam) and custom OAuth bindings in one list, so a shared identity
source can be spotted without opening user management account by account.
- The sign-up source is marked out. Custom OAuth reads it straight from the
binding table; built-in identities are back-filled from register_method in the
registration log. When neither path has it — old accounts, pruned logs — no
source is marked rather than guessed, and the sign-up method is returned
alongside the account so password-only sign-ups are still visible.
- Binding details follow the same privilege check user management applies:
accounts the caller cannot manage return statistics only, so an admin cannot
read root's identities from the risk-control page.
- The classic UI shows this read-only. A single binding is shown inline; with
several, only the sign-up source is listed plus "+N view all", which opens a
read-only detail dialog. No unbind action — this page is for judgement, the
disposition stays a manual decision.