fix(auth): Support single-org login in Auth V2 - #125130
Open
evanpurkhiser wants to merge 1 commit into
Open
evanpurkhiser wants to merge 1 commit into
evanpurkhiser wants to merge 1 commit into
Conversation
evanpurkhiser
added a commit
that referenced
this pull request
Sep 22, 2026
Single-organization mode currently returns only a redirect from `/auth/config/` for anonymous sessions. Auth V2 needs the normal login context to decide whether to offer password authentication or require SSO. Return the normal context with `singleOrganizationSlug` in single-org mode. Authenticated sessions continue to receive only `nextUri`. Backend tests cover both response shapes. This backend change should land before the [frontend single-org login PR](#125130).
Single-org installations need the login page to select their configured organization while still offering password authentication when SSO is optional or absent. Keep the organization fixed in the login UI and route to its canonical URL.
evanpurkhiser
force-pushed
the
git/fix-auth-support-single-org-login-in-auth-v2
branch
from
September 22, 2026 18:03
1f15ab0 to
9b948a6
Compare
evanpurkhiser
marked this pull request as ready for review
September 22, 2026 18:03
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Auth V2 currently sends anonymous single-organization users through an organization redirect that prevents the login page from showing password authentication when SSO is optional or absent. Once
/auth/config/returnssingleOrganizationSlugwith the normal login context, the UI can show the appropriate sign-in methods.Route the generic login page to the configured organization with a history replacement, retain password login for single-org installations without required SSO, and hide controls that would clear the only organization context. Also export the Auth V2 cookie-state helper used by the authenticated API error handler. React tests cover password-only, optional SSO, required SSO, and an authenticated user without organization access.
Dependency: backend auth-config PR #125132 must land first. Browser acceptance tests are prepared separately because Sentry requires frontend and backend/test changes in separate PRs.