Skip to content

Fix OIDC site-access policy updates - #3

Merged
chen21019 merged 1 commit into
mainfrom
fix/oidc-access-policy-save
Sep 15, 2026
Merged

chen21019 merged 1 commit into
mainfrom
fix/oidc-access-policy-save

Conversation

@chen21019

Copy link
Copy Markdown

Summary:

  • Separate access-policy-only changes from OIDC identity-source initialization.
  • Require fresh local recovery only for initial enablement, provider switches, and identity-source changes.
  • Require an actor-, purpose-, and digest-bound one-time MFA confirmation for access expansion.
  • Clear unrestricted allowlists, validate and deduplicate OIDC principals, and return stable error codes.
  • Bump Authentication Service to v0.4.37 and align release documentation and gates.

Validation:

  • go test ./... passed.
  • Focused policy, persistence, discovery-suppression, stable-error, and bound-confirmation tests are included.
  • Codex Security diff scan reported zero reportable findings.

@chen21019
chen21019 requested a review from a team as a code owner September 15, 2026 09:15
@chen21019
chen21019 force-pushed the fix/oidc-access-policy-save branch from 75e0b35 to 07ba641 Compare September 15, 2026 09:25
@chen21019
chen21019 merged commit 48c3f9e into main Sep 15, 2026
4 checks passed
@chen21019
chen21019 deleted the fix/oidc-access-policy-save branch September 15, 2026 09:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant