From d52ed339ba57870f4b9aecf27b53277363ae56b1 Mon Sep 17 00:00:00 2001 From: AlexFucuson9 Date: Tue, 30 Jun 2026 08:14:05 +0700 Subject: [PATCH] fix(cli): skip auto-SSO redirect for password-only auth providers Fixes #55130 _auto_sso_response() redirects unauthenticated HTML loads directly to /auth/login when exactly one provider is registered. For password-only providers (e.g. basic), /auth/login calls start_login() which raises NotImplementedError, producing HTTP 500. Check supports_password on the sole provider and return None (fall through to the normal /login page with the password form) when it is a password-only provider. --- hermes_cli/dashboard_auth/middleware.py | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/hermes_cli/dashboard_auth/middleware.py b/hermes_cli/dashboard_auth/middleware.py index 2c5f5b4f7b958..0cb4feaba48a2 100644 --- a/hermes_cli/dashboard_auth/middleware.py +++ b/hermes_cli/dashboard_auth/middleware.py @@ -185,6 +185,11 @@ def _auto_sso_response(request: Request) -> Response | None: from hermes_cli.dashboard_auth.prefix import prefix_from_request provider = providers[0] + # Password-only providers (e.g. basic) have no OAuth redirect flow; + # /auth/login would call start_login() which raises NotImplementedError. + # Let the normal /login page render instead. + if getattr(provider, "supports_password", False): + return None prefix = prefix_from_request(request) next_param = _safe_next_target(request) from urllib.parse import quote