Skip to content

test(webui): add standalone SSO session and multi-user isolation coverage - #6849

Merged
italic-jinxin merged 7 commits into
mainfrom
issue-4636-sso-e2e
Jul 30, 2026
Merged

italic-jinxin merged 7 commits into
mainfrom
issue-4636-sso-e2e

Conversation

@italic-jinxin

Copy link
Copy Markdown
Contributor

Summary

  • Adds a guarded, loopback-only OAuth endpoint seam for hermetic debug E2E builds while keeping default and release builds fail-closed.
  • Exercises provider discovery, login, callback, ticket exchange, session access, and logout through a standalone ironclaw serve process.
  • Verifies that two SSO identities in the same tenant cannot enumerate or read each other's threads, timelines, or SSE event streams.
  • Keeps the feature-enabled SSO test binary separate from the default binary used by live-canary artifact packaging.

Change Type

  • Bug fix
  • New feature
  • Refactor
  • Documentation
  • CI/Infrastructure
  • Security
  • Dependencies

Linked Issue

Closes #4636

Validation

  • cargo fmt --all -- --check
  • cargo clippy -p ironclaw --features e2e-test-support --all-targets -- -D warnings
  • cargo test -p ironclaw --features e2e-test-support --bin ironclaw — 464 passed
  • Default and feature-enabled SSO configuration tests — 19 passed in each mode
  • Standalone SSO and multi-user isolation E2E — 1 passed
  • E2E manifest validation — 21 tests complete
  • Workflow YAML parsing, Python compilation, and git diff --check
  • Agent self-review completed

Test Strategy

User behavior:

A user can complete SSO login through the standalone server, exchange the login ticket for a session bearer, access protected WebUI APIs, and log out. Two admitted users in the same tenant remain isolated.

Risk areas:

  • Model behavior
  • Browser authentication redirects
  • Side effect
  • Persistence
  • Security or permissions
  • External provider boundary
  • Cross-component behavior

Tests added or updated:

  • Unit or contract: endpoint pairing, feature gating, release/debug gating, and loopback URL validation.
  • Integration: standalone server authentication and protected-route coverage.
  • Recorded fixture: Not applicable; the OAuth provider is a local deterministic mock.
  • Browser E2E: Not applicable; no DOM behavior changed and the browser-shaped redirect flow is exercised directly over HTTP.
  • Backend or runtime: standalone binary, session authentication, owner-scoped thread/timeline/SSE access, and logout revocation.
  • Live canary: Not applicable; the acceptance criteria explicitly require avoiding an external OAuth provider.

What the tests prove:

The shipping server path can complete a hermetic SSO session flow, maps distinct provider identities to distinct users, denies cross-user thread/timeline/event-stream access, and revokes only the logged-out session.

Commands run:

  • cargo fmt --all -- --check
  • cargo clippy -p ironclaw --features e2e-test-support --all-targets -- -D warnings
  • cargo test -p ironclaw --features e2e-test-support --bin ironclaw
  • cargo test -p ironclaw --features e2e-test-support serve_sso -- --nocapture
  • pytest tests/e2e/scenarios/test_reborn_webui_v2_sso.py -v --timeout=120
  • python3 scripts/ci/check-reborn-responses-e2e-manifest.py
  • git diff --check

Security Impact

Yes, but test-only. The endpoint override requires an explicit Cargo feature, a debug build, paired environment variables, and HTTP loopback IP literals without URL credentials. Default and release builds reject activation. Mock credentials and identities are local test data and are not written to artifacts.

Trust-Boundary Checklist

  • Public trust-bearing types: Not applicable; no public policy types were added.
  • Prompt envelopes: Not applicable; no prompt construction changed.
  • Hash purpose: Not applicable; no security hashes were added.
  • Status or policy variants: Not applicable; no variants changed.
  • Serialization defaults: Not applicable; no durable fields changed.
  • Bounds: the mock identity queue is finite and supplied explicitly by the fixture.
  • Errors: invalid or unsafe endpoint configuration fails startup explicitly.
  • Naming: the feature and environment variables identify the seam as test-only.

Database Impact

None. No schema, migration, persistence format, or backend behavior changes.

Blast Radius

Limited to the WebUI SSO test seam, Python E2E harness, and the E2E/coverage workflows. Default runtime behavior is unchanged unless the test feature and guarded environment variables are explicitly enabled.

Rollback Plan

Revert the E2E commit followed by the test-seam commit. No data rollback or migration is required.

Review Follow-Through

Self-review identified missing explicit SSE isolation coverage. The E2E now verifies that cross-user stream attempts receive only a redacted not_found stream error and no business events. No remaining actionable findings are known.


Review track: C

@italic-jinxin italic-jinxin added size: XL 500+ changed lines risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Jul 29, 2026
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6849 July 29, 2026 10:39 Destroyed
@italic-jinxin

Copy link
Copy Markdown
Contributor Author

@claude review

@github-actions github-actions Bot added scope: ci CI/CD workflows scope: docs Documentation size: L 200-499 changed lines risk: medium Business logic, config, or moderate-risk modules and removed size: XL 500+ changed lines risk: low Changes to docs, tests, or low-risk modules labels Jul 29, 2026
@coderabbitai

coderabbitai Bot commented Jul 29, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d7059918-d337-4beb-8e9f-20626c584528

📥 Commits

Reviewing files that changed from the base of the PR and between b63d04e and 1f251dd.

📒 Files selected for processing (7)
  • .github/workflows/coverage.yml
  • .github/workflows/reborn-e2e.yml
  • crates/ironclaw_reborn_cli/Cargo.toml
  • crates/ironclaw_reborn_cli/src/commands/serve_sso.rs
  • tests/e2e/CLAUDE.md
  • tests/e2e/conftest.py
  • tests/e2e/scenarios/test_reborn_webui_v2_sso.py
 _________________________________
< Never fear, CodeRabbit is here! >
 ---------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
📝 Walkthrough

Walkthrough

Adds a guarded local Google OAuth endpoint seam, queued mock OIDC identities, a dedicated SSO binary, and standalone Reborn WebUI v2 E2E coverage for authentication, multi-user isolation, SSE denial, and logout revocation.

Changes

Reborn standalone SSO coverage

Layer / File(s) Summary
Guarded Google endpoint override
crates/ironclaw_reborn_cli/Cargo.toml, crates/ironclaw_reborn_cli/src/commands/serve_sso.rs
Adds the e2e-test-support feature, loopback-only endpoint validation, provider wiring, fail-closed configuration checks, and unit tests.
Queued mock OIDC identities
tests/e2e/fixtures/mock_oauth_idp.py
Adds queued identity profiles, client-bound authorization codes, and Google-shaped ID tokens to the local OAuth fixture.
SSO binary and server harness
tests/e2e/conftest.py, tests/e2e/reborn_webui_harness.py
Builds the debug SSO binary and starts Reborn with listener-derived URLs, Google SSO configuration, and two mock identities.
CI execution and isolation scenario
.github/workflows/*.yml, tests/e2e/scenarios/test_reborn_webui_v2_sso.py, tests/e2e/reborn_coverage_tests.txt, tests/e2e/README.md, tests/e2e/CLAUDE.md
Runs the default and SSO binaries, executes the new scenario, and validates distinct sessions, scope isolation, SSE denial, and logout behavior.

Estimated code review effort: 4 (Complex) | ~60 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Browser
  participant MockOAuthIdp
  participant RebornServe
  participant WebChatAPI
  Browser->>RebornServe: Request Google login
  RebornServe-->>Browser: Redirect to MockOAuthIdp
  Browser->>MockOAuthIdp: Authorize Alice or Bob
  MockOAuthIdp-->>Browser: Callback with authorization code
  Browser->>MockOAuthIdp: Exchange authorization code
  MockOAuthIdp-->>Browser: Google-shaped id_token
  Browser->>RebornServe: Exchange login ticket
  RebornServe-->>Browser: Session bearer token
  Browser->>WebChatAPI: Access threads, timelines, and SSE
  WebChatAPI-->>Browser: Scoped data or not_found
  Browser->>RebornServe: Logout
  RebornServe-->>Browser: Alice session revoked
Loading

Possibly related PRs

Suggested reviewers: serrrfirat

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title uses Conventional Commits style and accurately summarizes the new SSO session and multi-user isolation coverage.
Description check ✅ Passed The description matches the template and covers summary, change type, linked issue, validation, strategy, security, rollback, and review follow-through.
Linked Issues check ✅ Passed The PR satisfies #4636 by adding a hermetic standalone SSO flow, two-user isolation checks, logout revocation, and a test-only OAuth seam.
Out of Scope Changes check ✅ Passed The workflow, test harness, feature flag, docs, and scenario changes all support the linked SSO E2E objective without obvious unrelated additions.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@ironloopai

ironloopai Bot commented Jul 29, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Review · PR #6849

🟢 Completed · Review submitted

Submitted review →

Reviewed the complete trusted base-to-head comparison. No concrete, actionable correctness, security, CI, or test-coverage defects were found. The test OAuth seam remains off by default, requires the explicit feature in a debug build, validates paired literal-loopback endpoints, and the workflows preserve the default binary separately from the SSO test binary.

Automatic · PR opened · attempt 1 of 3 · completed in 1m 31s

Run details
  • Repository: nearai/ironclaw
  • Base: main at a0e91d1
  • Head: issue-4636-sso-e2e at b63d04e
  • Created: Jul 29, 2026, 10:44 AM UTC
  • Updated: Jul 29, 2026, 10:46 AM UTC
  • Run: b39b43f8-7ca9-4e44-ad22-f148f28ccbb8
  • Latest attempt: 1 · Completed · 7e8a9963-b071-4970-9de5-a18b2ac743f0

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Review complete · PR #6849

✅ No actionable findings

Reviewed the complete trusted base-to-head comparison. No concrete, actionable correctness, security, CI, or test-coverage defects were found. The test OAuth seam remains off by default, requires the explicit feature in a debug build, validates paired literal-loopback endpoints, and the workflows preserve the default binary separately from the SSO test binary.

Validation and technical details
  • Inspected all 11 changed files and surrounding CLI OAuth-provider, Google token-decoding, E2E fixture, harness, manifest, and workflow code.
  • Verified the comparison with git diff refs/ironloop/base..refs/ironloop/head and git diff --check; no whitespace errors were reported.
  • Python byte-compilation succeeded for all changed Python files.
  • scripts/ci/check-reborn-responses-e2e-manifest.py passed with 21 tests.
  • Rust tests could not be executed because cargo is unavailable in the review environment; pytest collection and workflow YAML parsing were also unavailable because pytest/PyYAML or Ruby are not installed.
  • Base: main
  • Head: issue-4636-sso-e2e at b63d04e
  • Run: b39b43f8-7ca9-4e44-ad22-f148f28ccbb8

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 6

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_reborn_cli/Cargo.toml`:
- Around line 35-40: Update the Cargo feature comment to state the approved
feature bar that justifies enabling this dev-only seam, and rename
e2e-test-support to the existing test-support seam consistently across
conftest.py, both workflows, and all cfg(feature = ...) references; preserve the
current dependency activation and debug/loopback gating.

In `@crates/ironclaw_reborn_cli/src/commands/serve_sso.rs`:
- Around line 240-255: Add a caller-level test under #[cfg(feature =
"e2e-test-support")] that invokes sso_startup_config_from_env with Google test
endpoints configured but IRONCLAW_REBORN_WEBUI_GOOGLE_CLIENT_ID absent, and
assert startup aborts with an error mentioning that environment variable. Keep
the test focused on the fail-closed branch in the provider setup flow.
- Around line 346-363: Remove build_google_provider and fold the test-endpoint
selection into its call site, using the normal GoogleProvider::new construction
for default builds and GoogleProvider::with_endpoints only when e2e-test-support
is enabled. Do not add a #[cfg(not(feature = ...))] fallback or panic path;
validate both default and e2e-test-support builds.

In `@tests/e2e/CLAUDE.md`:
- Line 145: Update the reborn_v2_sso_server row in the session-scoped fixture
table to mark it as module-scoped, matching the reborn_v2_server row above, and
identify tests/e2e/reborn_webui_harness.py as the defining module.

In `@tests/e2e/conftest.py`:
- Around line 487-515: Both feature variants overwrite target/debug/ironclaw, so
isolate the SSO build and simplify the workflow build steps. In
tests/e2e/conftest.py lines 487-515, update ironclaw_reborn_sso_binary to use
target/e2e-sso, build with that target directory, return
target/e2e-sso/debug/ironclaw, and remove unlink/copy logic. In
.github/workflows/reborn-e2e.yml lines 311-323, remove the restore/canary
packaging workaround and trust comment, leaving plain builds with separate
target directories. In .github/workflows/coverage.yml lines 242-251, likewise
remove rm/copy/restore steps and build each variant into its own target
directory.

In `@tests/e2e/scenarios/test_reborn_webui_v2_sso.py`:
- Around line 176-185: The cross-user SSE denial checks in the scenario
currently use httpx response buffering, making them depend on the stream closing
promptly. Replace the /events requests in the alice_streams_bob and
bob_streams_alice flow with the existing aiohttp-based sse_stream() helper, then
assert the denied stream_error frame through that incremental SSE path while
preserving both cross-user denial checks.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 763d4037-8b09-418b-84b2-59e576257fa7

📥 Commits

Reviewing files that changed from the base of the PR and between a0e91d1 and b63d04e.

📒 Files selected for processing (11)
  • .github/workflows/coverage.yml
  • .github/workflows/reborn-e2e.yml
  • crates/ironclaw_reborn_cli/Cargo.toml
  • crates/ironclaw_reborn_cli/src/commands/serve_sso.rs
  • tests/e2e/CLAUDE.md
  • tests/e2e/README.md
  • tests/e2e/conftest.py
  • tests/e2e/fixtures/mock_oauth_idp.py
  • tests/e2e/reborn_coverage_tests.txt
  • tests/e2e/reborn_webui_harness.py
  • tests/e2e/scenarios/test_reborn_webui_v2_sso.py

Comment thread crates/ironclaw_reborn_cli/Cargo.toml Outdated
Comment thread crates/ironclaw_reborn_cli/src/commands/serve_sso.rs Outdated
Comment thread crates/ironclaw_reborn_cli/src/commands/serve_sso.rs Outdated
Comment thread tests/e2e/CLAUDE.md Outdated
Comment thread tests/e2e/conftest.py
Comment thread tests/e2e/scenarios/test_reborn_webui_v2_sso.py Outdated
@github-actions

github-actions Bot commented Jul 29, 2026 •

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 85.55% (315532 / 368828 lines)
  floor:    85.11% (tolerance 0.5pp -> effective floor 84.61%)
  denominator: 368828 lines now vs 360961 at floor capture (+7867 lines, +2.18%) — not a material change

RATCHET PASS: ironclaw_runner
  observed: 86.88% (14671 / 16887 lines)
  floor:    83.58% (tolerance 0.5pp -> effective floor 83.08%)
  floor_covered_lines: 13083 (tolerance 20 lines -> effective floor 13063)
  denominator: 16887 lines now vs 15653 at floor capture (+1234 lines, +7.88%) — material change (>5%)

RATCHET PASS: ironclaw_processes
  observed: 88.05% (5838 / 6630 lines)
  floor:    82.29% (tolerance 0.5pp -> effective floor 81.79%)
  floor_covered_lines: 5140 (tolerance 20 lines -> effective floor 5120)
  denominator: 6630 lines now vs 6246 at floor capture (+384 lines, +6.15%) — material change (>5%)

RATCHET PASS: ironclaw_turns
  observed: 86.21% (9453 / 10965 lines)
  floor:    85.36% (tolerance 0.5pp -> effective floor 84.86%)
  floor_covered_lines: 9181 (tolerance 20 lines -> effective floor 9161)
  denominator: 10965 lines now vs 10755 at floor capture (+210 lines, +1.95%) — not a material change

⚠️ 2 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_prompt_envelope, ironclaw_scripts

Reborn integration-tier coverage

Line coverage (Reborn crates): 85.55% — 315532 / 368828 lines

Per-crate breakdown (60 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_prompt_envelope 0% 0 / 88
ironclaw_scripts 0% 0 / 345
ironclaw_process_sandbox 34.38% 120 / 349
ironclaw_host_ingress 42.5% 17 / 40
ironclaw_event_projections 43.51% 684 / 1572
ironclaw_libsql_runtime 59.91% 127 / 212
ironclaw_observability 61.54% 16 / 26
ironclaw_authorization 63.02% 610 / 968
ironclaw_memory 64.41% 959 / 1489
ironclaw_telegram_v2_adapter 69.69% 731 / 1049
ironclaw_trust 73.21% 664 / 907
ironclaw_wasm_limiter 74.6% 47 / 63
ironclaw_extractors 74.72% 538 / 720
ironclaw_capabilities 74.95% 2882 / 3845
ironclaw_projects 76.48% 400 / 523
ironclaw_mcp 76.6% 779 / 1017
ironclaw_filesystem 77.55% 5990 / 7724
ironclaw_reborn_cli 78.44% 10874 / 13862
ironclaw_wasm 79.72% 735 / 922
ironclaw_llm 80.82% 23319 / 28854
ironclaw_memory_native 81.02% 3299 / 4072
ironclaw_auth 81.88% 6679 / 8157
ironclaw_first_party_extensions 82.38% 6682 / 8111
ironclaw_host_api 83.68% 9728 / 11625
ironclaw_events 83.8% 1536 / 1833
ironclaw_reborn_identity 83.8% 450 / 537
ironclaw_operator 84.41% 5561 / 6588
ironclaw_secrets 84.56% 2798 / 3309
ironclaw_network 85.09% 959 / 1127
ironclaw_reborn_config 85.23% 2101 / 2465
ironclaw_skills 85.27% 4493 / 5269
ironclaw_telegram_extension 85.4% 1299 / 1521
ironclaw_extension_host 85.52% 19926 / 23299
ironclaw_approvals 86.08% 1818 / 2112
ironclaw_triggers 86.11% 2803 / 3255
ironclaw_turns 86.21% 9453 / 10965
ironclaw_reborn_composition 86.23% 22037 / 25556
ironclaw_webui 86.37% 11171 / 12934
ironclaw_hooks 86.73% 9950 / 11473
ironclaw_runner 86.88% 14671 / 16887
ironclaw_common 86.99% 1772 / 2037
ironclaw_reborn_event_store 87.19% 1327 / 1522
ironclaw_extensions 87.45% 4927 / 5634
ironclaw_product 87.49% 21354 / 24406
ironclaw_reborn_openai_compat 88% 3724 / 4232
ironclaw_processes 88.05% 5838 / 6630
ironclaw_reborn_traces 88.13% 11987 / 13601
ironclaw_threads 88.57% 4943 / 5581
ironclaw_host_runtime 89.09% 20539 / 23054
ironclaw_slack_extension 89.26% 2027 / 2271
ironclaw_conversations 90.03% 3171 / 3522
ironclaw_resources 90.84% 4474 / 4925
ironclaw_loop_host 90.93% 17735 / 19505
ironclaw_event_streams 91.24% 1063 / 1165
ironclaw_attachments 93.06% 630 / 677
ironclaw_outbound 93.91% 4101 / 4367
ironclaw_agent_loop 94.42% 10422 / 11038
ironclaw_safety 95.22% 3941 / 4139
ironclaw_first_party_extension_ports 95.71% 3837 / 4009
ironclaw_runtime_policy 96.56% 814 / 843

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (3 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_embeddings v1-only: consumed only by root ironclaw (src/app.rs, src/tools/builtin/memory.rs, src/workspace/mod.rs, src/config/{mod,embeddings}.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657

@railway-app

railway-app Bot commented Jul 29, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-6849 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 30, 2026 at 10:54 am

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6849 July 29, 2026 11:22 Destroyed
@coderabbitai

coderabbitai Bot commented Jul 29, 2026

Copy link
Copy Markdown

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
putComment timed out

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6849 July 29, 2026 11:46 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6849 July 29, 2026 12:05 Destroyed
@italic-jinxin italic-jinxin self-assigned this Jul 30, 2026
# Conflicts:
#	tests/e2e/CLAUDE.md
#	tests/e2e/reborn_coverage_tests.txt
#	tests/e2e/reborn_webui_harness.py
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6849 July 30, 2026 05:03 Destroyed
hanakannzashi
hanakannzashi previously approved these changes Jul 30, 2026
@italic-jinxin
italic-jinxin added this pull request to the merge queue Jul 30, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Jul 30, 2026
@italic-jinxin
italic-jinxin added this pull request to the merge queue Jul 30, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Jul 30, 2026
# Conflicts:
#	tests/e2e/reborn_webui_harness.py
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6849 July 30, 2026 10:45 Destroyed
@italic-jinxin
italic-jinxin added this pull request to the merge queue Jul 30, 2026
Merged via the queue into main with commit e35ba16 Jul 30, 2026
62 checks passed
@italic-jinxin
italic-jinxin deleted the issue-4636-sso-e2e branch July 30, 2026 12:44
l3ocifer pushed a commit to l3ocifer/frick-ironclaw that referenced this pull request Sep 3, 2026
…rage (nearai#6849)

* test(webui): add guarded SSO provider E2E seam

* test(e2e): cover WebUI SSO multi-user isolation

* fix(test): address SSO E2E review feedback

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-6849 — 414f03d0 Deployed Jul 30, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: ci CI/CD workflows scope: docs Documentation size: L 200-499 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Test] Add standalone SSO session and multi-user isolation E2E coverage

2 participants