Skip to content

feat(signin): wire /signin chooser into login flow + relabel buttons - #2606

Merged
jung-thomas merged 1 commit into
DEVfrom
feature/signin-flow-wiring
Oct 2, 2026
Merged

jung-thomas merged 1 commit into
DEVfrom
feature/signin-flow-wiring

Conversation

@jung-thomas

Copy link
Copy Markdown
Contributor

What & why

Wires the standalone /signin IdP-chooser page into the actual login flow and relabels its two buttons. Previously the chooser was orphaned — the shellbar sign-in action went straight to /login, which (with dynamicIdentityProvider + a default IdP) jumps directly to one IdP and never shows the chooser.

Changes

  • hugo/layouts/signin.html — relabel buttons:
    • "Sign in with SAP" → "Sign in with SAP Account" (href /login?sap_idp=sap.default unchanged)
    • "Sign in with SAP Universal ID" → "Sign In if you don't already have an SAP Account" (href /login?sap_idp=sap.custom unchanged)
    • Forward a safe relative returnTo onto the chosen /login?sap_idp=… URL (open-redirect guard mirrors login-redirect.html).
  • hugo/layouts/partials/header.html — the shellbar profile-click (anonymous → deliberate sign-in) now redirects to /signin?returnTo=… so the user picks an IdP. maybeAutoLogin (silent returning-visitor SSO, Research the login Hanlding #1689) deliberately left on /login — it must resolve transparently against an existing IdP SSO session and must not surface a chooser.
  • hugo-apps/src/app-space/AppSpace.vue — the App Space step-1 instruction "Log in with your SAP ID" is now a live sign-in link while anonymous (same /signin flow via startLogin()); reverts to a passive label once isLoggedIn. (Addresses Tom's follow-up on the app-space page.)
  • docs/developers/architecture/authentication.md — document the chooser-in-flow behavior, returnTo forwarding, and the auto-login carve-out.
  • test/e2e/signin.spec.ts — update button-label assertions to the new labels (self-skips without SMOKE_BASE_URL).

Design notes

  • The AppRouter has no config knob to force unauthenticated protected-route hits through a custom chooser — its xsuaa redirect goes straight to XSUAA's /oauth/authorize. So "wire /signin into the flow" is implemented at the deliberate sign-in entry points (shellbar profile-click + app-space step 1), not via protected-route interception. This is the low-risk interpretation matching the approved design and avoids fighting the AppRouter auth handler.
  • sap_idp keys unchanged (sap.default / sap.custom) — confirmed correct.

Testing

  • Unit suite green locally (exit 0).
  • Real verification is post-DEV-deploy: Hugo + island rebuild (build:all) renders the island bundle; test:e2e validates the chooser labels/hrefs. Not deploy-tested on this branch (golden rule: never deploy a feature branch).

🤖 Generated with Claude Code

Relabel the two IdP-chooser buttons and route the deliberate sign-in
action through the /signin chooser instead of straight to one IdP.

- signin.html: buttons → "Sign in with SAP Account" and "Sign In if you
  don't already have an SAP Account" (hrefs/sap_idp keys unchanged);
  forward a safe relative returnTo onto the chosen /login?sap_idp URL.
- header.html: shellbar profile-click (anonymous) → /signin?returnTo=…
  so the user picks an IdP. maybeAutoLogin (silent returning-visitor
  SSO, #1689) still targets /login directly — must not surface a chooser.
- AppSpace.vue: step-1 "Log in with your SAP ID" is now a live sign-in
  link while anonymous (same /signin flow); passive label once logged in.
- authentication.md: document the chooser-in-flow + returnTo forwarding.
- e2e/signin.spec.ts: update button-label assertions to new labels.
@jung-thomas
jung-thomas merged commit f136a3a into DEV Oct 2, 2026
4 of 5 checks passed
@jung-thomas
jung-thomas deleted the feature/signin-flow-wiring branch October 2, 2026 20:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant