Repository navigation
feat: fill user info for externalIdp auth - #4247
Conversation
|
Codex Review: Didn't find any major issues. 🎉 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7be47f1e48
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| )} | ||
| </div> | ||
| {login ? ( | ||
| {user ? ( |
There was a problem hiding this comment.
Route SSO logout through the meta endpoint
When an ExternalIdp user opens any non-home route, useMetaAuth() is false because it is based on the current page, so the logout button newly enabled by this condition invokes window.api.auth.logout() (/logout) rather than metaLogout() (/meta/logout). Since the SSO session was established through /meta/oidc/authorize, the meta session remains active and the user cannot reliably sign out; select the logout backend from user.isSso rather than the current route.
AGENTS.md reference: AGENTS.md:L89-L89
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
On non-home multi-cluster routes, AuthAPI.getPath('/logout') does not send a bare request to an unrelated backend. With clusterName, it resolves to <metaBackend>/proxy/cluster/<clusterName>/logout. ydb-em routes both /proxy/.../logout and /meta/.../logout through THandlerActorApiProxyRequest_Logout; that handler revokes the OIDC tokens, deletes the OIDC session, and clears the same Path=/ session cookie. Therefore, the session created through /meta/oidc/authorize is also cleared by the proxy logout path. Selecting the endpoint from user.isSso would duplicate the existing routing logic and couple an authentication type to a transport choice, so no code change is needed here.
Resolves https://github.com/ydb-platform/ydb-em/issues/258
CI Results
Test Status:⚠️ FLAKY
📊 Full Report
😟 No changes in tests. 😕
Bundle Size: 🔺
Current: 65.46 MB | Main: 65.45 MB
Diff: +0.01 MB (0.02%)
ℹ️ CI Information