HeySummitH
HeySummit
5h ago

Pre-registration password to create a private event

We have an event tomorrow and the client wanted to use a Global password to protect the event. However the platform will currently let anyone into the event wether you have a password set or not. If you register you get the “thanks for registering and email has been sent….” then you can click the “Back to event” butotn and youre in without the system requiring you to enter a password. This goes againt the the actual purpose of a password. To give this client some security, we turned on the password feature in our embedded streaming player. Can we please have a gatekeeper built into the registration page that demand you enter the password during the rego process. If its just random passwords then they click their email and have to enter it when they are sent back to the platform or if its a global password, they enter it during their registration process.
ReviewingReviewing

4 hours ago

Agreed, this will be even more important as the lobby gets rolled out and enhanced in functionality.

4 hours ago

Hi Luke, just want to make sure I'm understanding what you're writing here. Essentially, whether you use our password feature or magic links, you can still only access the event if you have completed registration for the event itself. And so I'm a little bit confused as to your point about the platform letting anyone in to the event whether they have a password or not. Obviously if they've registered, that does give them immediate access to the event once they've registered. If they were to come back later, say the next day or when the event starts, then they would of course be asked to either log in with their magic link or to provide a password if you turn that feature on. Your note about building a password into the registration flow itself. Are you saying that when an attendee registers for the very first time, to even complete the registration, you'd want them to be able to provide a password to continue? If you can help me understand the above, that would be incredibly helpful. Many thanks

4 hours ago

Hi Ben, im reffering to securing access to an event to only those who have the password. We have an event on HS tomorrow morning in which the client wanted to lock down to staff only by sing a password that would be distrubted via internal email. The idea being that only people with his password could successfully register to watch the event. Having a password field as part of the registration fields is what would then allow that registration to be successful. Its a gateway to the event itself. Currently the password feature is If anyone can register to get access to the event then its not truely secure. Its just registration, not authentication To your questions ”Are you saying that when an attendee registers for the very first time, to even complete the registration, you'd want them to be able to provide a password to continue?” my answer is yes, exactly.

4 hours ago

Gotcha, thanks for clarifying Luke. I'm not entirely sure if this is something that would make sense for us to add, though I will give it further consideration. In the meantime, a feature you might find more useful for your case if you want to restrict access to registrations is to use the ability to limit access to either individual email addresses or a particular email domain. That way you can literally block anyone who doesn't have an example.com email address (for example) from registering in the first place.

4 hours ago

Hi Ben, Please do consider it. A passwords job is to gatekeep access. Currently, even with a password set, anyone can can access to an event without having to enter password during registration so the password did not stop them. I understand we can limit by email address and this would work in some instances where you know all domains being used but wont work for all events.

4 hours ago

Thanks, Luke. Really appreciate the extra context there. The password capabilities we have at the moment are for registered attendees to access the event, rather than determining whether the general public can even access or register for the events in the first place. If we were to roll out a higher-level password that kicks in even before an attendee registers, would your preference be to have that asked at the beginning of the registration or before they even see the event pages? I.e., if they were to go to the landing page, would your preference be to show a pop-up saying that this is a restricted event and ask for a password at that point, or is it purely before they start registering that you would prefer that to be kicked in?