I suggest to limit authorisation for the current GitHub organisation, or at least add a parameter which allow to provide GitHub organisation name. Current behaviour is unsecure - every GtHub user can authenticate.
my issue is duplicated to https://issues.jenkins-ci.org/browse/JENKINS-51657
Agree - This should be addressed so that only a specific organization can even login.
Duplicated by JENKINS-46962