Skip to content

feat: implement button "login with SSO" - #4242

Merged
kkdras merged 5 commits into
mainfrom
kkdras.257
Aug 18, 2026
Merged

kkdras merged 5 commits into
mainfrom
kkdras.257

Conversation

@kkdras

@kkdras kkdras commented Aug 17, 2026 •

Copy link
Copy Markdown
Contributor

Resolves #247

CI Results

Test Status: ⚠️ FLAKY

📊 Full Report

Total Passed Failed Flaky Skipped
876 872 0 4 0
Test Changes Summary ✨1 🗑️18

✨ New Tests (1)

  1. Nodes tab shows nodes table with memory viewer (tenant/diagnostics/tabs/nodes.test.ts)

🗑️ Deleted Tests (18)

  1. TenantOverview — empty tenant info shows an inline response error (errorDisplay/errorDisplay.test.ts)
  2. TenantOverview — empty refresh keeps the last valid overview (errorDisplay/errorDisplay.test.ts)
  3. renders the PDisk State and Maintenance legends (storage/vdiskColoring.test.ts)
  4. renders storage group PDisks by State without allocation fill (storage/vdiskColoring.test.ts)
  5. renders the first storage group PDisk row in state mode (storage/vdiskColoring.test.ts)
  6. renders the first storage group PDisk row in space mode (storage/vdiskColoring.test.ts)
  7. renders the first storage group PDisk row in drive mode (storage/vdiskColoring.test.ts)
  8. renders the first storage group PDisk row in decommit mode (storage/vdiskColoring.test.ts)
  9. renders the first storage group PDisk row in maintenance mode (storage/vdiskColoring.test.ts)
  10. renders the first storage group PDisk row in device mode (storage/vdiskColoring.test.ts)
  11. monitoring user sees the owning table link for DataShard (tablet/tabletObjectLink.test.ts)
  12. monitoring user sees the owning topic link for PersQueue (tablet/tabletObjectLink.test.ts)
  13. monitoring user sees the owning topic link for PersQueueReadBalancer (tablet/tabletObjectLink.test.ts)
  14. user without monitoring permission does not request or see the object (tablet/tabletObjectLink.test.ts)
  15. legacy user without monitoring permission flag sees the object (tablet/tabletObjectLink.test.ts)
  16. incomplete Hive data omits the link without breaking tablet info (tablet/tabletObjectLink.test.ts)
  17. shows nodes table with memory viewer on database page (tenant/diagnostics/tabs/nodes.test.ts)
  18. shows nodes table with memory viewer on diagnostics page (tenant/diagnostics/tabs/nodes.test.ts)

Bundle Size: 🔺

Current: 65.46 MB | Main: 65.46 MB
Diff: +6.14 KB (0.01%)

⚠️ Bundle size increased. Please review.

ℹ️ CI Information
  • Test recordings for failed tests are available in the full report.
  • Bundle size is measured for the entire 'dist' directory.
  • 📊 indicates links to detailed reports.
  • 🔺 indicates increase, 🔽 decrease, and ✅ no change in bundle size.

@kkdras

kkdras commented Aug 17, 2026

Copy link
Copy Markdown
Contributor Author

@greptile review
@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1542910950

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/store/reducers/capabilities/hooks.ts Outdated
}

export function createSsoAuthorizeUrl(host: string, returnTo: string) {
const url = new URL('/meta/oidc/authorize', `https://${host}`);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Build the authorize URL from the configured meta backend

In the documented multi-cluster setup where REACT_APP_META_BACKEND can be a different URL such as http://your-meta-host:8765, BaseMetaAPI fetches capabilities from that configured backend, but this line redirects to https://<current UI host>/meta/oidc/authorize. The SSO button consequently targets the wrong host and protocol; derive the authorize endpoint from the configured meta-backend base while preserving its scheme and path prefix.

AGENTS.md reference: AGENTS.md:L489-L493

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The current URL is intentional and follows #257: the UI and YDB Meta are expected to use the same host.
Using REACT_APP_META_BACKEND is not enough for a separate or prefixed backend. After SSO, the browser returns to /meta/oidc/callback, where the session cookie is created. If Meta uses another host, the cookie will belong to that host rather than the UI host.
Supporting a separate Meta host or /api/meta3 requires additional proxy/backend integration, so it is outside the scope of this change.

Comment thread src/store/reducers/capabilities/hooks.ts Outdated
@kkdras
kkdras marked this pull request as ready for review August 17, 2026 11:29

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3d116e071f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/containers/Authentication/utils.ts Outdated
}

&__button-sso {
margin-top: 8px;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

let's use variable

const isDirectAuthPage = Boolean(useRouteMatch({path: routes.auth, exact: true}));

const needDatabase = useLoginWithDatabase();
useMetaCapabilitiesQuery();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's better wrap Authentication with GetMetaCapabilities (see src/containers/App/Content)

@kkdras
kkdras requested a review from Raubzeug August 18, 2026 11:55
@kkdras
kkdras added this pull request to the merge queue Aug 18, 2026
Merged via the queue into main with commit 51a2d66 Aug 18, 2026
17 checks passed
@kkdras
kkdras deleted the kkdras.257 branch August 18, 2026 13:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants