Authorize org membership from the local mirror - #2026
Merged
Merged
Conversation
RhysSullivan
added this pull request to stack #2027
September 16, 2026 16:27
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ✅ Deployment successful! View logs |
executor-cloud | 59d4c4c | Sep 16 2026, 06:25 PM |
Contributor
Cloudflare previewTorn down — the PR is closed. |
@executor-js/cli
@executor-js/config
@executor-js/execution
@executor-js/sdk
@executor-js/codemode-core
@executor-js/runtime-quickjs
@executor-js/plugin-file-secrets
@executor-js/plugin-graphql
@executor-js/plugin-keychain
@executor-js/plugin-mcp
@executor-js/plugin-onepassword
@executor-js/plugin-openapi
executor
commit: |
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
executor-marketing | 59d4c4c | Commit Preview URL Branch Preview URL |
Sep 16 2026, 06:24 PM |
RhysSullivan
force-pushed
the
member-directory/auth-cutover
branch
2 times, most recently
from
September 16, 2026 17:40
0b1a8e4 to
a0b4ac5
Compare
RhysSullivan
force-pushed
the
member-directory/auth-cutover
branch
from
September 16, 2026 18:01
a0b4ac5 to
0aed526
Compare
RhysSullivan
force-pushed
the
member-directory/auth-cutover
branch
2 times, most recently
from
September 16, 2026 18:02
1c5bed6 to
a23935a
Compare
RhysSullivan
force-pushed
the
member-directory/auth-cutover
branch
from
September 16, 2026 18:11
a23935a to
1dcd612
Compare
RhysSullivan
force-pushed
the
member-directory/auth-cutover
branch
2 times, most recently
from
September 16, 2026 18:16
b42b53c to
667af6e
Compare
RhysSullivan
force-pushed
the
member-directory/auth-cutover
branch
from
September 16, 2026 18:23
667af6e to
13eadd3
Compare
RhysSullivan
force-pushed
the
member-directory/auth-cutover
branch
from
September 16, 2026 18:23
13eadd3 to
59d4c4c
Compare
RhysSullivan
marked this pull request as ready for review
September 16, 2026 18:30
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Layer 5 of 5. Cloud only. Takes WorkOS off the per-request path.
authorizeOrganizationreadsMemberDirectory.membershipinstead of calling WorkOS. Active status required; role mapping unchanged. Admin gates on the account, admin, and org planes use the role the authorize step resolved. The membership ownership check on remove and role change is one point read. The org switcher and free-org limit readmembershipsOf.deploy.ymlrunsscripts/ensure-workos-mirror-ready.tsafter migrations. It runs the backfill if needed, drains the events stream itself, and fails the deploy if the mirror is still not ready.auth.authorize_organizationspan stamped withmirror.readyandmirror.readiness, so the WorkOS fallback rate is one Axiom query (recipe added to the prod-telemetry skill).Ops step (cloud): add
WORKOS_API_KEYto theproductionGitHub environment so the deploy gate can run the backfill. Removal in the WorkOS dashboard now takes effect when the event lands, normally seconds and at most about a minute. Removal through Executor stays immediate.