Skip to content

feat(auth): allow disabling password login when OIDC SSO is active - #10889

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.50from
MeRezaRezaei:feat/oidc-disable-password-login
Aug 21, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.50from
MeRezaRezaei:feat/oidc-disable-password-login

Conversation

@MeRezaRezaei

Copy link
Copy Markdown
Contributor

Summary

When OIDC SSO is configured and active, operators may want to enforce SSO across all dashboard users and disallow traditional password login.

This PR adds the oidcDisablePasswordLogin configuration option (and OMNIROUTE_OIDC_DISABLE_PASSWORD_LOGIN / OIDC_DISABLE_PASSWORD_LOGIN feature flags) to safely disable the password login form while OIDC is enabled.

Changes

  • Settings & Schema: Added oidcDisablePasswordLogin boolean to settings schema and default settings.
  • Login API: /api/auth/login rejects password authentication requests when oidcDisablePasswordLogin is active, logging an audit event.
  • Login Page UI: Displays only the OIDC SSO action and hides/disables password login fields when password login is disabled.
  • Bootstrap API: /api/settings/require-login reports the oidcDisablePasswordLogin flag to the client.
  • Unit Tests: Added coverage for password login disabler in tests/unit/auth-login-route.test.ts, tests/unit/login-bootstrap-route.test.ts, and tests/unit/feature-flags-settings.test.ts.

When OIDC is enabled, password login can be disabled (via the
oidcDisablePasswordLogin setting or the OMNIROUTE_OIDC_DISABLE_PASSWORD_LOGIN
feature flag) so dashboard users authenticate only through OIDC SSO.

Recovered from a stash left by a previous session and separated into its own
branch per request. Also prunes now-stale eslint suppressions for the settings
and auth/login routes whose restricted @/lib/localDb imports were replaced with
specific @/lib/db/* module imports (which is what the rule requires).
@diegosouzapw
diegosouzapw merged commit e4a2417 into diegosouzapw:release/v3.8.50 Aug 21, 2026
4 of 5 checks passed
diegosouzapw pushed a commit that referenced this pull request Aug 21, 2026
backryun added a commit to backryun/OmniRoute that referenced this pull request Aug 21, 2026
…NDALONE_DIR vars

Three merged features read env vars that were never added to
.env.example / ENVIRONMENT.md, breaking the env-doc contract gate
(check-env-doc-sync + issue-7793 repro test) on release/v3.8.50:

- KIMI_WEB_BASE_URL / KIMI_WEB_CHAT_URL — Kimi Web executor overrides
  (diegosouzapw#10944 moved the default to www.kimi.ai but never documented the
  override knobs)
- OMNIROUTE_OIDC_DISABLE_PASSWORD_LOGIN (+ bare alias
  OIDC_DISABLE_PASSWORD_LOGIN) — OIDC-only login flag (diegosouzapw#10889)
- OMNIROUTE_STANDALONE_DIR — build-time standalone output override
  (scripts/build/colocate-standalone.mjs, diegosouzapw#10936)

check-env-doc-sync.mjs now reports "✓ Env / docs contract is in sync"
and both sync tests pass 15/15.
backryun added a commit to backryun/OmniRoute that referenced this pull request Aug 21, 2026
…NDALONE_DIR vars

Three merged features read env vars that were never added to
.env.example / ENVIRONMENT.md, breaking the env-doc contract gate
(check-env-doc-sync + issue-7793 repro test) on release/v3.8.50:

- KIMI_WEB_BASE_URL / KIMI_WEB_CHAT_URL — Kimi Web executor overrides
  (diegosouzapw#10944 moved the default to www.kimi.ai but never documented the
  override knobs)
- OMNIROUTE_OIDC_DISABLE_PASSWORD_LOGIN (+ bare alias
  OIDC_DISABLE_PASSWORD_LOGIN) — OIDC-only login flag (diegosouzapw#10889)
- OMNIROUTE_STANDALONE_DIR — build-time standalone output override
  (scripts/build/colocate-standalone.mjs, diegosouzapw#10936)

check-env-doc-sync.mjs now reports "✓ Env / docs contract is in sync"
and both sync tests pass 15/15.
backryun added a commit to backryun/OmniRoute that referenced this pull request Aug 21, 2026
…NDALONE_DIR vars

Three merged features read env vars that were never added to
.env.example / ENVIRONMENT.md, breaking the env-doc contract gate
(check-env-doc-sync + issue-7793 repro test) on release/v3.8.50:

- KIMI_WEB_BASE_URL / KIMI_WEB_CHAT_URL — Kimi Web executor overrides
  (diegosouzapw#10944 moved the default to www.kimi.ai but never documented the
  override knobs)
- OMNIROUTE_OIDC_DISABLE_PASSWORD_LOGIN (+ bare alias
  OIDC_DISABLE_PASSWORD_LOGIN) — OIDC-only login flag (diegosouzapw#10889)
- OMNIROUTE_STANDALONE_DIR — build-time standalone output override
  (scripts/build/colocate-standalone.mjs, diegosouzapw#10936)

check-env-doc-sync.mjs now reports "✓ Env / docs contract is in sync"
and both sync tests pass 15/15.
backryun added a commit to backryun/OmniRoute that referenced this pull request Aug 22, 2026
…NDALONE_DIR vars

Three merged features read env vars that were never added to
.env.example / ENVIRONMENT.md, breaking the env-doc contract gate
(check-env-doc-sync + issue-7793 repro test) on release/v3.8.50:

- KIMI_WEB_BASE_URL / KIMI_WEB_CHAT_URL — Kimi Web executor overrides
  (diegosouzapw#10944 moved the default to www.kimi.ai but never documented the
  override knobs)
- OMNIROUTE_OIDC_DISABLE_PASSWORD_LOGIN (+ bare alias
  OIDC_DISABLE_PASSWORD_LOGIN) — OIDC-only login flag (diegosouzapw#10889)
- OMNIROUTE_STANDALONE_DIR — build-time standalone output override
  (scripts/build/colocate-standalone.mjs, diegosouzapw#10936)

check-env-doc-sync.mjs now reports "✓ Env / docs contract is in sync"
and both sync tests pass 15/15.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…gosouzapw#10889)

Validado no worktree combinado: typecheck:core, changelog-integrity, complexity, cognitive-complexity, file-size, lint e testes focados (auth-login-route, login-bootstrap-route, feature-flags-settings — corrigi EXPECTED_FEATURE_FLAG_COUNT 51→52 fix-in-place, novo flag adicionado sem atualizar a própria contagem) todos verdes. CI vermelho é o base-red já rastreado em diegosouzapw#9985. Obrigado!
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants