Skip to content

feat(auth): add opt-in OIDC browser member admission - #91

Open
juancarlosm wants to merge 1 commit into
plannotator:mainfrom
ackstorm:feat/oidc-auto-admission
Open

juancarlosm wants to merge 1 commit into
plannotator:mainfrom
ackstorm:feat/oidc-auto-admission

Conversation

@juancarlosm

@juancarlosm juancarlosm commented Oct 9, 2026 •

Copy link
Copy Markdown

A successful OIDC browser login currently rejects users who have no Artifact Server membership, even when the issuer already restricts access to a corporate directory. Add opt-in normal-member admission with ARTIFACT_SERVER_OIDC_AUTO_ADMIT and an optional exact email-domain registration list. Manual admission remains the default.

Preserve administrator bootstrap, existing roles, and inactive-member denial when a bound subject changes its email. Apply the policy only to the configured OIDC browser flow; bearer/MCP, WorkOS, and local-owner admission retain their existing behavior. Recover the same-email first-login race reproduced against PostgreSQL replicas. Wire the policy through CLI, Worker/D1, and Helm without schema changes or new dependencies.

Validation: 374 root tests, 41 Worker tests, focused PostgreSQL concurrency/deactivation tests, build, lint, type checking, conformance validation, and Helm rendering passed locally. The full fork pipeline passed Linux iteration checks, macOS portability, packaged deployment checks, and image publication. The fork's publishing workflow and AWS RDS certificate checksum refresh are excluded from this PR.

Closes #89.

@juancarlosm
juancarlosm marked this pull request as ready for review October 10, 2026 03:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature]: Opt-in automatic member admission after successful OIDC login

1 participant