docs: correct the SSO, LDAP, OneDrive and MCP tutorials against the OAuth provider registration and sign-out code - #1435
Open
silentoplayz wants to merge 1 commit into
Conversation
silentoplayz
force-pushed
the
docs/sso-tutorial-pages
branch
2 times, most recently
from
September 25, 2026 05:39
aa8d520 to
ae60d7d
Compare
…Auth provider registration and sign-out code
silentoplayz
force-pushed
the
docs/sso-tutorial-pages
branch
from
September 25, 2026 05:48
ae60d7d to
e4e0aad
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
I compared the SSO tutorials, the LDAP guide, the OneDrive page and the MCP Notion page with the OAuth provider registration, sign-out and LDAP code.
OPENID_PROVIDER_URLregisters nothing withoutOAUTH_CLIENT_ID. Sign-out discovers the end-session endpoint from the session's provider, soOPENID_PROVIDER_URLis not required for Microsoft logout (removed from the Entra page too). Login callback URIs come from*_REDIRECT_URIor the request, notWEBUI_URL, which only sets where the browser lands after sign-in. The rest of the dual OAuth page (description, overview, configuration logic) now matches, and so do the Entra test step and the OneDrive toggle wording.OAUTH_GROUPS_CLAIM(the old name is a fallback). An empty claim touches nothing, andOAUTH_BLOCKED_GROUPSare never changed.LDAP_USE_TLSmeans LDAPS from connect (no STARTTLS), and in Docker certificates go throughLDAP_CA_CERT_FILE: without it the LDAP client uses the CA store of the machine or container it runs in, and a container does not see the host's store.ENABLE_ONEDRIVE_INTEGRATION=trueseeds the admin toggle on a fresh database. The toggle only overrides it once a stored value exists.Related issue or discussion
None.
Checklist
Notes for reviewers
Sources on
dev:config.py(load_oauth_providers,OAUTH_GROUPS_CLAIM,DEFAULT_CONFIG),routers/auths.py(sign-out metadata lookup, the LDAPTlsandServercalls), andutils/oauth.py(update_user_groups,redirect_uri). Also the commit that removed the admin guard (a1aceb5f8, first tag v0.8.11),models/config.py(seed_defaults), andsrc/lib/components/AddToolServerModal.svelte.