Skip to content

fix: preserve OIDC access policy across restart - #6

Merged
chen21019 merged 2 commits into
mainfrom
fix/oidc-policy-restart-persistence
Sep 19, 2026
Merged

chen21019 merged 2 commits into
mainfrom
fix/oidc-policy-restart-persistence

Conversation

@chen21019

Copy link
Copy Markdown

Result\n- stop the one-time legacy settings migration once encrypted auth.config exists\n- preserve OIDC access mode and allowlist across authentication-service and Server restarts\n- retain the legacy migration path for installations that have not created auth.config\n- add a deterministic regression test that rejects any legacy setting access after migration\n- bump release/readme/security-gate coordinates to v0.4.40\n\n## QA evidence that exposed the bug\nOn Server v1.6.446, a restricted oidc_user/oidc_group allowlist saved and read back correctly, then became empty immediately after restarting the same container. Startup audit events showed UpgradeSettings writing api.auth.allowed.identities from OIDC's absent legacy mapping.\n\n## Acceptance\nCI must run the full Go/race/validation/security gates. The released binary will then be packaged into a new immutable Server patch and verified on 10.0.0.125:8080 with save -> restart -> readback, Authentik TOTP, Passkey, policy switching, token ownership, and cross-tab tests. No production or HAProxy changes.

@chen21019
chen21019 requested a review from a team as a code owner September 19, 2026 21:33
@chen21019
chen21019 merged commit 25b075b into main Sep 19, 2026
4 checks passed
@chen21019
chen21019 deleted the fix/oidc-policy-restart-persistence branch September 19, 2026 21:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant