From c439f2940704131177b02b982a484fca563e0956 Mon Sep 17 00:00:00 2001 From: roroghost17 Date: Wed, 27 May 2026 18:44:00 +0530 Subject: [PATCH] feat: removes SSO gate check for temp token auth --- framework/oauth2/main.go | 1 - transports/bifrost-http/lib/config_test.go | 4 +- ui/app/workspace/config/views/mcpView.tsx | 54 +++++++++------------- 3 files changed, 26 insertions(+), 33 deletions(-) diff --git a/framework/oauth2/main.go b/framework/oauth2/main.go index 1cf5231b53f..eb113d3a663 100644 --- a/framework/oauth2/main.go +++ b/framework/oauth2/main.go @@ -921,7 +921,6 @@ func generateSecureRandomString(length int) (string, error) { // The function errors out cleanly on any misconfig (missing identity, unknown // mode, missing template config) — no fallbacks, no generated identities. func (p *OAuth2Provider) InitiateUserOAuthFlow(ctx context.Context, oauthConfigID string, mcpClientID string, redirectURI string, flowMode schemas.MCPAuthMode) (*schemas.OAuth2FlowInitiation, string, error) { - // 1. Load template OAuth config. templateConfig, err := p.configStore.GetOauthConfigByID(ctx, oauthConfigID) if err != nil { diff --git a/transports/bifrost-http/lib/config_test.go b/transports/bifrost-http/lib/config_test.go index e933d6f0a30..5566dc3b79a 100644 --- a/transports/bifrost-http/lib/config_test.go +++ b/transports/bifrost-http/lib/config_test.go @@ -1318,7 +1318,9 @@ func (m *MockConfigStore) UpdateMCPPerUserHeaderFlow(ctx context.Context, flow * func (m *MockConfigStore) DeleteMCPPerUserHeaderFlowsByModeIdentityAndMCPClient(ctx context.Context, mode schemas.MCPAuthMode, identity, mcpClientID string) error { return nil } -func (m *MockConfigStore) DeleteMCPPerUserHeaderFlow(ctx context.Context, id string) error { return nil } +func (m *MockConfigStore) DeleteMCPPerUserHeaderFlow(ctx context.Context, id string) error { + return nil +} func (m *MockConfigStore) ListAllPendingMCPPerUserHeaderFlows(ctx context.Context) ([]tables.TableMCPPerUserHeaderFlow, error) { return nil, nil } diff --git a/ui/app/workspace/config/views/mcpView.tsx b/ui/app/workspace/config/views/mcpView.tsx index 9d60b4877f8..0bfbc3b3e70 100644 --- a/ui/app/workspace/config/views/mcpView.tsx +++ b/ui/app/workspace/config/views/mcpView.tsx @@ -16,7 +16,6 @@ import { SelectValue, } from "@/components/ui/select"; import { Switch } from "@/components/ui/switch"; -import { IS_ENTERPRISE } from "@/lib/constants/config"; import { getErrorMessage, useGetCoreConfigQuery, @@ -25,7 +24,6 @@ import { import { CoreConfig, DefaultCoreConfig } from "@/lib/types/config"; import { EnvVar } from "@/lib/types/schemas"; import { RbacOperation, RbacResource, useRbac } from "@enterprise/lib"; -import { useGetAuthTypeQuery } from "@enterprise/lib/store/apis/scimApi"; import { AlertTriangle } from "lucide-react"; import { useCallback, useEffect, useMemo, useState } from "react"; import { toast } from "sonner"; @@ -41,13 +39,9 @@ export default function MCPView() { RbacOperation.Update, ); const { data: bifrostConfig } = useGetCoreConfigQuery({ fromDB: true }); - const { data: authType } = useGetAuthTypeQuery(undefined, { - skip: !IS_ENTERPRISE, - }); const config = bifrostConfig?.client_config; const [updateCoreConfig, { isLoading }] = useUpdateCoreConfigMutation(); const [localConfig, setLocalConfig] = useState(DefaultCoreConfig); - const isSCIMEnabled = IS_ENTERPRISE && authType?.type === "sso"; const [localValues, setLocalValues] = useState<{ mcp_agent_depth: string; @@ -292,32 +286,30 @@ export default function MCPView() { /> - {isSCIMEnabled && ( - /* Temp Token Auth */ -
-
- -

- When enabled, per-user MCP OAuth links can include a short-lived - scoped token so someone without an active Bifrost dashboard - session can complete the flow. Keep disabled to require normal - dashboard authentication. -

-
- + {/* Temp Token Auth */} +
+
+ +

+ When enabled, per-user MCP OAuth links can include a short-lived + scoped token so someone without an active Bifrost dashboard + session can complete the flow. Keep disabled to require normal + dashboard authentication. +

- )} + +
{/* Code Mode Binding Level */}