From 3ac3c8b7b1d26f13ab4c3c8ab5de8fb05e53cb85 Mon Sep 17 00:00:00 2001 From: chen21019 <19357113+chen21019@users.noreply.github.com> Date: Mon, 21 Sep 2026 10:34:38 +0800 Subject: [PATCH] Publish OIDC member types in v1 schema --- docs/releases/orchestration-engine-0.183.310.md | 5 +++-- resources/content/schema/base/projectMember.json | 4 +++- scripts/check-pasturestack-source | 2 ++ 3 files changed, 8 insertions(+), 3 deletions(-) diff --git a/docs/releases/orchestration-engine-0.183.310.md b/docs/releases/orchestration-engine-0.183.310.md index 2a72e07731..82c2a2f216 100644 --- a/docs/releases/orchestration-engine-0.183.310.md +++ b/docs/releases/orchestration-engine-0.183.310.md @@ -4,8 +4,9 @@ identity types even when an older database setting overrides the packaged external identity list and omits them. - Union the same built-in types into the `projectMember.externalIdType` options - published by both API generations, preserving stable order and eliminating - the runtime/schema mismatch. + published by the dynamic API schema and add them to the frozen v1 base + schema, preserving stable order and eliminating the runtime/schema mismatch + in both API generations. - Retain the configured external-provider requirement and reject every unknown external identity type. This is an upgrade compatibility repair, not a broad identity-type bypass. diff --git a/resources/content/schema/base/projectMember.json b/resources/content/schema/base/projectMember.json index a677451243..78e0e1542e 100644 --- a/resources/content/schema/base/projectMember.json +++ b/resources/content/schema/base/projectMember.json @@ -23,7 +23,9 @@ "openldap_user", "openldap_group", "azuread_user", - "azuread_group" + "azuread_group", + "oidc_user", + "oidc_group" ] } } diff --git a/scripts/check-pasturestack-source b/scripts/check-pasturestack-source index 777aed1d0c..ddfca38dd2 100755 --- a/scripts/check-pasturestack-source +++ b/scripts/check-pasturestack-source @@ -164,6 +164,8 @@ require_line code/implementation/docker/machine/src/test/java/io/cattle/platform require_line resources/content/schema/token/token-auth.json ' "token.authProvider": "cr",' require_line resources/content/schema/token/token-auth.json ' "token.clientSessionId": "cro",' require_line resources/content/cattle-global.properties 'auth.service.external.id.types=github_user,github_org,github_team,shibboleth_user,shibboleth_group,ldap_user,ldap_group,oidc_user,oidc_group' +require_line resources/content/schema/base/projectMember.json ' "oidc_user",' +require_line resources/content/schema/base/projectMember.json ' "oidc_group"' require_line code/packaging/app-config/src/main/java/io/cattle/platform/app/TypesConfig.java ' @DependsOn("ArchaiusStartup")' require_line code/framework/schema/src/test/java/io/cattle/platform/schema/processor/TokenSessionAuthOverlayTest.java ' public void clientSessionIdSurvivesAuthorizationAsCreateOnlyInput() throws Exception {' require_line resources/src/test/java/io/cattle/platform/resources/FrozenTokenSessionSchemaTest.java ' public void everyFrozenSchemaWithTokenAcceptsClientSessionIdOnlyOnCreate()'