Repository navigation
Conversation
|
@blueorangutan package |
|
@Damans227 a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress. |
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #13867 +/- ##
=========================================
Coverage 19.91% 19.91%
- Complexity 20198 20212 +14
=========================================
Files 6373 6373
Lines 577230 577257 +27
Branches 70696 70701 +5
=========================================
+ Hits 114936 114981 +45
+ Misses 449736 449712 -24
- Partials 12558 12564 +6
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 18842 |
|
@blueorangutan test |
|
@DaanHoogland a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests |
|
[SF] Trillian Build Failed (tid-16750) |
|
@blueorangutan package |
|
@kiranchavala can you review this? fixes #13859 and #13860 you raised |
5b0ceca to
68a60b7
Compare
Fixes #13859. Fixes #13860.
oauth2.plugins.excludewas only checked once, at Spring bean registration time, byExtensionRegistry. A config change didn't take effect without a restart. Even a restart didn't reliably help. The exclude value may not be loaded from the DB yet when the registry beans initialize. The registry also has no concept of domain at all.This replaces that with a live check in
OAuth2AuthManagerImpl. It runs on every login/verify attempt instead of once at boot.isProviderExcluded(providerName, domainId)checks the globaloauth2.plugins.excludelist first. If a domainId is given, it then checks a new domain-scoped override of the same key.oauth2.plugins.excludeis nowConfigKey.Scope.Domain(strict scope, no hierarchy walking). It can be set per domain in addition to globally.getUserOAuth2AuthenticationProvider()gained a(providerName, domainId)overload. BothOAuth2UserAuthenticator.authenticate()andOAuth2AuthManagerImpl.verifySecretCodeAndFetchEmail()use it, since those are the two places that resolve a provider for an actual login attempt. The existing single-arg overload still exists. It delegates withdomainId = null, global scope only.listUserOAuth2AuthenticationProviders()now filters out excluded providers too.listOauthProviderstops reporting an excluded provider as available.Added test coverage for the union logic, the domain-scoped config key, and both call sites.