njtrafficsignshopper
njtrafficsignshopper@lemmy.world
Joined
3 posts • 26 comments
Homestar runner
There would not be a need to duplicate or sync all user databases across the fediverse to support SSO. In fact SSO already exists in other contexts and I haven’t heard of any implementation that works that way. It’s essentially accomplished by the authority and the service exchanging login tokens.
That seems to me to be one of the big issues - it looks like the available themes are down to the discretion of the instance admin. I dunno if allowing an arbitrary URL for a theme would be too much of a security hole, but it seems like that would quickly make each user able to use any theme they want.