We use LDAP for authentication and use a separate LDAP group for each repository access.
For example there is repoA repository and "repo_a" LDAP group. If a user belongs to that group then he can access repoA.
Assume that user X belongs to repo_a and user Y don't. If user X fork repoA (we want to work with forking workflow), then he can add user Y to his fork. Since his fork also is repoA, we don't want user Y to access repoA because user Y is not in repo_a group.
Is there a way to prevent users to add any developer to their fork?