Skip to content

feat(sso): classify an SSO configuration as authentication only - #807

Merged
dorsha merged 5 commits into
mainfrom
feat/sso-authentication-only
Sep 27, 2026
Merged

dorsha merged 5 commits into
mainfrom
feat/sso-authentication-only

Conversation

@dorsha

@dorsha dorsha commented Sep 19, 2026 •

Copy link
Copy Markdown
Member

Description

Adds authenticationOnly to the SSO settings types — SSOSAMLSettings, SSOSAMLByMetadataSettings and SSOOIDCSettings — and surfaces it on the SSO settings responses.

A connection classified this way verifies a person's identity without creating, updating or signing in a user: the login authenticates against the IdP and returns the IdP response, with no user and no session behind it. See descope/backend#2713.

It is optional. Left out it is not sent, so an ordinary settings save keeps whatever the tenant configured instead of clearing it; false clears it. Setting it through any one protocol classifies the whole connection, including the tenant's default one.

Tests

configureSAMLSettings and configureOIDCSettings send it when set, send false explicitly so the classification can be cleared rather than dropped as a falsy value, and omit it entirely when the caller says nothing.

🤖 Generated with Claude Code

Adds sso.configureAuthenticationOnly and surfaces the classification on
the SSO settings responses.

An authentication-only SSO configuration verifies a person's identity
without creating, updating or signing in a user, so it grants no access
to the application. A tenant can then keep one connection for
application login and another purely to verify external people, and tell
them apart through the API.

ssoId is required: the tenant's default configuration cannot be
classified.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@shuni-bot

shuni-bot Bot commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

🐕 Shuni Review

No new issues found.

🤖 Model: claude-opus-5 · Effort: high


Review scope: Full review

Reviewed files (4)
  • README.md
  • lib/management/sso.test.ts
  • lib/management/sso.ts
  • lib/management/types.ts

🐕 Review complete — View session on Shuni Portal 🐾

🤖 Model: claude-opus-5 · Effort: high

@shuni-bot shuni-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🐕 Shuni review: no new findings. Every changed file in this pull request was reviewed.

The full review summary is in Shuni's sticky review comment on this pull request.

The classification is stored on the configuration's settings rows, which
the tenant's default configuration has too, so ssoId becomes optional
and moves after the required argument: omit it to target the default.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

@shuni-bot shuni-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🐕 Shuni review: no new findings. Every changed file in this pull request was reviewed.

The full review summary is in Shuni's sticky review comment on this pull request.

The dedicated method is gone. The classification is per SSO connection, so it
now travels on the SAML, by-metadata and OIDC settings objects like every other
per-connection setting. Left out it is not sent, so an ordinary settings save
keeps whatever the tenant configured instead of clearing it.

@shuni-bot shuni-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🐕 Shuni review: no new findings. Every changed file in this pull request was reviewed.

The full review summary is in Shuni's sticky review comment on this pull request.

@dorsha dorsha left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review against backend#2713. configureSAMLSettings and configureSAMLByMetadata post settings whole and configureOIDCSettings spreads it, so nothing is dropped and false is preserved; tests assert the wire body; loadSettings / loadAllSettings hit the v2 routes and return SSOSettings, which carries the field. Nothing blocking.

  • Parity gap shared with go-sdk#855: XAASettings has no authenticationOnly and configureXAASettings picks fields explicitly, so the backend's ConfigureXAASettingsRequest.authenticationOnly is unreachable from this SDK.
  • README shows disableSignRequest in the SSO section (1094-1101); add authenticationOnly beside it with the omit / false semantics.
  • Nit: no test for configureSAMLByMetadata, and none pinning that authenticationOnly survives transformSettingsResponse on load.

Comment thread lib/management/types.ts
The OIDC settings type doubles as the oidc field of the load response, where the
server never sets the classification. Without a note a reader checks the nested
field and silently gets false.

@shuni-bot shuni-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🐕 Shuni review: no new findings. Every changed file in this pull request was reviewed.

The full review summary is in Shuni's sticky review comment on this pull request.

configureXAASettings picks its request fields explicitly, so XAASettings had
no way to express the classification and it would have been dropped even if
a caller passed it. Adds the by-metadata, Cross-App Access and load-decoding
tests, and documents the omit-keeps / false-clears semantics in the README.
@dorsha

dorsha commented Sep 23, 2026

Copy link
Copy Markdown
Member Author

Added authenticationOnly to XAASettings and listed it in configureXAASettings — that method picks its request fields explicitly, so the field would have been dropped even if a caller passed it. Checked against undefined rather than truthiness so false still reaches the server to clear the classification.

Also the tests that were missing: configureSAMLByMetadata sends it, the Cross-App Access save sends it and omits it when unset, and loadSettings keeps it through transformSettingsResponse. README documents the omit-keeps / false-clears semantics. 39 tests pass in lib/management/sso.test.ts.

@shuni-bot shuni-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🐕 Shuni review: no new findings. Every changed file in this pull request was reviewed.

The full review summary is in Shuni's sticky review comment on this pull request.

@dorsha
dorsha merged commit 6f94db8 into main Sep 27, 2026
29 checks passed
@dorsha
dorsha deleted the feat/sso-authentication-only branch September 27, 2026 08:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant