Skip to content

fix(auth): Support single-org login in Auth V2 - #125130

Open
evanpurkhiser wants to merge 1 commit into
masterfrom
git/fix-auth-support-single-org-login-in-auth-v2
Open

evanpurkhiser wants to merge 1 commit into
masterfrom
git/fix-auth-support-single-org-login-in-auth-v2

Conversation

@evanpurkhiser

@evanpurkhiser evanpurkhiser commented Sep 21, 2026 •

Copy link
Copy Markdown
Member

Auth V2 currently sends anonymous single-organization users through an organization redirect that prevents the login page from showing password authentication when SSO is optional or absent. Once /auth/config/ returns singleOrganizationSlug with the normal login context, the UI can show the appropriate sign-in methods.

Route the generic login page to the configured organization with a history replacement, retain password login for single-org installations without required SSO, and hide controls that would clear the only organization context. Also export the Auth V2 cookie-state helper used by the authenticated API error handler. React tests cover password-only, optional SSO, required SSO, and an authenticated user without organization access.

Dependency: backend auth-config PR #125132 must land first. Browser acceptance tests are prepared separately because Sentry requires frontend and backend/test changes in separate PRs.

@github-actions github-actions Bot added the Scope: Frontend Automatically applied to PRs that change frontend components label Sep 21, 2026
evanpurkhiser added a commit that referenced this pull request Sep 22, 2026
Single-organization mode currently returns only a redirect from
`/auth/config/` for anonymous sessions. Auth V2 needs the normal login
context to decide whether to offer password authentication or require
SSO.

Return the normal context with `singleOrganizationSlug` in single-org
mode. Authenticated sessions continue to receive only `nextUri`. Backend
tests cover both response shapes.

This backend change should land before the [frontend single-org login
PR](#125130).
Single-org installations need the login page to select their configured organization while still offering password authentication when SSO is optional or absent. Keep the organization fixed in the login UI and route to its canonical URL.
@evanpurkhiser
evanpurkhiser force-pushed the git/fix-auth-support-single-org-login-in-auth-v2 branch from 1f15ab0 to 9b948a6 Compare September 22, 2026 18:03
@evanpurkhiser
evanpurkhiser marked this pull request as ready for review September 22, 2026 18:03
@evanpurkhiser
evanpurkhiser requested review from a team as code owners September 22, 2026 18:03

This branch was successfully deployed

1 active deployment
Preview — 9b948a69 Deployed Sep 22, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Scope: Frontend Automatically applied to PRs that change frontend components

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant