Skip to content

feat: add organization policy enforcement - #135

Open
kishore7snehil wants to merge 4 commits into
mainfrom
feat/org-policy-enforcement
Open

kishore7snehil wants to merge 4 commits into
mainfrom
feat/org-policy-enforcement

Conversation

@kishore7snehil

Copy link
Copy Markdown
Contributor

📋 Changes

This PR adds organization policy enforcement to auth0-api-python, letting an API require that incoming access tokens carry an org_id claim and optionally pin accepted tokens to a specific organization or allowlist.

✨ Features

  • Organization Policy: New organization_policy option on ApiClientOptions. "allow" accepts tokens with or without org_id and matches existing behavior. "required" rejects tokens without org_id.
  • Organization Pinning: New organization_id option that pins accepted tokens to a single organization or an allowlist. Valid only when the policy is "required".
  • Policy Enforcement: verify_access_token() now enforces the configured organization policy during verification.
  • Missing Organization Error: New MissingOrganizationError (subclasses VerifyAccessTokenError), raised when a token has no org_id and the policy is "required".
  • Organization Not Allowed Error: New OrganizationNotAllowedError (subclasses VerifyAccessTokenError), raised when a token's org_id is not in the organization_id allowlist.

🔧 API Changes

  • Added organization_policy (str, default "allow") to ApiClientOptions
  • Added organization_id (str or list of str, default None) to ApiClientOptions, valid only with the "required" policy
  • New errors: MissingOrganizationError, OrganizationNotAllowedError (both subclass VerifyAccessTokenError)
  • verify_access_token() now enforces the organization policy

📖 Documentation

  • Added docs/OrganizationPolicy.md describing the policy modes and the organization allowlist
  • Updated README.md with an organization policy section

🧪 Testing

  • This change adds test coverage
  • This change has been tested on the latest version of the platform/language

Contributor Checklist

Adds organization_policy ("allow"/"required") and organization_id
allowlist options. When required, verify_access_token now rejects
tokens missing org_id or carrying an org_id outside the allowlist.
Passing organization_id with policy "allow" raises ConfigurationError
at construction time.
Adds coverage for missing org_id under "required" policy, org_id
outside the allowlist, an allowed org_id succeeding, default "allow"
policy not requiring org_id, and the construction-time ConfigurationError
when organization_id is set without policy "required". Each test is
co-located with the existing tests for the surface it exercises.
Top-level select/ignore/per-file-ignores are deprecated in current
ruff versions; rule sets are unchanged.
@kishore7snehil
kishore7snehil force-pushed the feat/org-policy-enforcement branch from 19320d8 to 8f87351 Compare October 5, 2026 16:32
@kishore7snehil
kishore7snehil marked this pull request as ready for review October 6, 2026 06:41
@kishore7snehil
kishore7snehil requested a review from a team as a code owner October 6, 2026 06:41

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant