feat(auth): opt-in flag to skip OIDC email_verified check for enterprise IdPs - #1859
Conversation
|
The two E2E failures look pre-existing on
I don't have permission to rerun the failed jobs — happy to rebase/retrigger if that helps once main is green. |
|
@royreznik This PR is a Bug fix, Feature, or UI / frontend change but the Demo section is missing or only contains a placeholder. These change types require a screenshot or screen recording so reviewers can see the new behaviour without checking out the branch. Please update the Demo section with:
Use |
|
@dhruv0811 Any comments? |
|
/review |
|
dhruv0811
left a comment
There was a problem hiding this comment.
Looks good! Sorry for the late reply :) Thanks for adding this!!
Standard Okta tiers (without custom API Access Management) omit the email_verified claim from id_tokens for directory-provisioned users, so the OIDC callback's hard reject breaks SSO for those deployments. Add OMNIGENT_OIDC_SKIP_EMAIL_VERIFICATION (default off): when set, accept the signed id_token email claim without requiring email_verified. Default path unchanged — absent/false claims still hard-reject. Enabling logs a startup warning plus an info line per bypassed login. GitHub OAuth unaffected. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
f8ca059 to
954ff5d
Compare
|
|
🏷️ Doc impact: Adds a new user-configurable OIDC deploy setting (OMNIGENT_OIDC_SKIP_EMAIL_VERIFICATION) that changes login/email-verification behavior, affecting the deploy/OIDC setup documentation. Drafting a docs PR to Auto-classified on merge. Set the label manually before merging to override. · run |
Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com>
* docs: document omnigent-ai/omnigent#1722 (#261) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: document omnigent-ai/omnigent#2018 (#265) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: document omnigent-ai/omnigent#1386 (#272) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: document omnigent-ai/omnigent#2156 (#278) * docs: document omnigent-ai/omnigent#2156 * Apply suggestion from @serena-ruan * Apply suggestions from code review Co-authored-by: Serena Ruan <82044803+serena-ruan@users.noreply.github.com> --------- Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> Co-authored-by: Serena Ruan <82044803+serena-ruan@users.noreply.github.com> * docs: document omnigent-ai/omnigent#2022 (#268) * docs: document omnigent-ai/omnigent#2022 * docs: add steering gif and simplify message queue section Co-authored-by: Isaac --------- Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> Co-authored-by: Serena Ruan <serena.rxy@gmail.com> * chore(api): sync openapi.json from omnigent@3c7a558 (#274) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: document omnigent-ai/omnigent#526 (#279) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: rename hindsight extra to memory (omnigent[memory]) (#282) The memory tools ship under the `memory` extra (omnigent[memory]), not `hindsight`. Update the install instruction and extra name to match. The Hindsight product name and the hindsight_* tool names are unchanged. * docs: document default base branch for new worktrees (#284) * docs: document default base branch for new worktrees * docs: condense worktree branches section and add setting demo gif Co-authored-by: Isaac --------- Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> Co-authored-by: Serena Ruan <serena.rxy@gmail.com> * chore(api): sync openapi.json from omnigent@7fb779f (#281) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * chore(api): sync openapi.json from omnigent@60e775a (#288) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: document omnigent-ai/omnigent#2152 (#280) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: document omnigent-ai/omnigent#1859 (#277) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: document omnigent-ai/omnigent#2135 (#276) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> --------- Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> Co-authored-by: Serena Ruan <82044803+serena-ruan@users.noreply.github.com> Co-authored-by: Serena Ruan <serena.rxy@gmail.com> Co-authored-by: Pat Sukprasert <pattara.sk127@gmail.com> Co-authored-by: Dhruv Gupta <dhruv.gupta@databricks.com>
…i#1859) Standard Okta tiers (without custom API Access Management) omit the email_verified claim from id_tokens for directory-provisioned users, so the OIDC callback's hard reject breaks SSO for those deployments. Add OMNIGENT_OIDC_SKIP_EMAIL_VERIFICATION (default off): when set, accept the signed id_token email claim without requiring email_verified. Default path unchanged — absent/false claims still hard-reject. Enabling logs a startup warning plus an info line per bypassed login. GitHub OAuth unaffected. Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Signed-off-by: Aditya Devarapalli <adityareddyd2@gmail.com>
* docs: document omnigent-ai/omnigent#1722 (#261) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: document omnigent-ai/omnigent#2018 (#265) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: document omnigent-ai/omnigent#1386 (#272) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: document omnigent-ai/omnigent#2156 (#278) * docs: document omnigent-ai/omnigent#2156 * Apply suggestion from @serena-ruan * Apply suggestions from code review Co-authored-by: Serena Ruan <82044803+serena-ruan@users.noreply.github.com> --------- Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> Co-authored-by: Serena Ruan <82044803+serena-ruan@users.noreply.github.com> * docs: document omnigent-ai/omnigent#2022 (#268) * docs: document omnigent-ai/omnigent#2022 * docs: add steering gif and simplify message queue section Co-authored-by: Isaac --------- Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> Co-authored-by: Serena Ruan <serena.rxy@gmail.com> * chore(api): sync openapi.json from omnigent@3c7a558 (#274) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: document omnigent-ai/omnigent#526 (#279) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: rename hindsight extra to memory (omnigent[memory]) (#282) The memory tools ship under the `memory` extra (omnigent[memory]), not `hindsight`. Update the install instruction and extra name to match. The Hindsight product name and the hindsight_* tool names are unchanged. * docs: document default base branch for new worktrees (#284) * docs: document default base branch for new worktrees * docs: condense worktree branches section and add setting demo gif Co-authored-by: Isaac --------- Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> Co-authored-by: Serena Ruan <serena.rxy@gmail.com> * chore(api): sync openapi.json from omnigent@7fb779f (#281) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * chore(api): sync openapi.json from omnigent@60e775a (#288) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: document omnigent-ai/omnigent#2152 (#280) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: document omnigent-ai/omnigent#1859 (#277) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: document omnigent-ai/omnigent#2135 (#276) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> * docs: document official kubernetes server image variant (#285) Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> --------- Co-authored-by: omnigent-ci[bot] <294685417+omnigent-ci[bot]@users.noreply.github.com> Co-authored-by: Serena Ruan <82044803+serena-ruan@users.noreply.github.com> Co-authored-by: Serena Ruan <serena.rxy@gmail.com> Co-authored-by: Pat Sukprasert <pattara.sk127@gmail.com> Co-authored-by: Dhruv Gupta <dhruv.gupta@databricks.com> Co-authored-by: Daniel Lok <daniel.lok@databricks.com>
Related issue
N/A
Summary
email_verifiedclaim fromid_tokens for directory-provisioned users. Omnigent's OIDC callback hard-rejects any token where the claim isn't affirmativelytrue, so SSO fails with a 400 ("Could not determine user email from IdP") for these deployments.OMNIGENT_OIDC_SKIP_EMAIL_VERIFICATION(default off): when set, the callback accepts the signedid_tokenemail claim without requiringemail_verified. The default path is unchanged — absent/false claims are still a hard reject, preserving the account-takeover protection for IdPs that allow user-asserted emails.ELI5: the server normally only trusts an email if the identity provider stamps it "verified". Okta's standard tier doesn't include that stamp for company-directory users even though the directory owns the address, so login breaks. This adds an opt-in switch for operators who trust their directory to say "accept the email without the stamp".
Test Plan
pytest tests/server/test_oidc_callback.py— 12 passed. New parametrized test drives the real callback route with a genuinely RS256-signedid_tokenthat omitsemail_verified(the Okta shape) and one withemail_verified: false; with the flag on, both mint a session for the correct email. All pre-existing rejection tests still pass, proving the default is unchanged.pre-commit runclean on all touched files.Demo
N/A (non-visual backend change)
Type of change
Test coverage
Coverage notes
New tests cover the flag-on path (absent and false claims); the existing
test_callback_unverified_email_rejectedmatrix locks the flag-off default.Changelog
OMNIGENT_OIDC_SKIP_EMAIL_VERIFICATION=1lets OIDC logins through when the IdP omits theemail_verifiedclaim (e.g. standard-tier Okta with directory-provisioned users)🤖 Generated with Claude Code