Skip to content

Fix OIDC identity link ownership - #42

Merged
chen21019 merged 1 commit into
mainfrom
fix/oidc-identity-link-owner
Sep 21, 2026
Merged

chen21019 merged 1 commit into
mainfrom
fix/oidc-identity-link-owner

Conversation

@chen21019

Copy link
Copy Markdown

Outcome

  • persist login credentials against the explicitly verified account and verify ownership after creation
  • exclude internal service accounts from identity-link login resolution
  • narrowly repair legacy links owned by the built-in token account only when provider, type, external ID, digest, and target identity all match
  • apply the same ownership invariant to identity-proof and provider-switch credentials

Verification

  • source release gate: PASS
  • Maven reactor through auth-logic: 38/38 modules PASS
  • auth-logic: 93 tests, 0 failures/errors
  • new ownership regression cases: 4/4 PASS

Runtime repeated-login and permission-matrix acceptance will run against the Server image that consumes this release before production use.

@chen21019
chen21019 requested a review from a team as a code owner September 21, 2026 08:36
@chen21019
chen21019 enabled auto-merge (squash) September 21, 2026 08:36
@chen21019
chen21019 merged commit 9faa58a into main Sep 21, 2026
5 checks passed
@chen21019
chen21019 deleted the fix/oidc-identity-link-owner branch September 21, 2026 08:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant