You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Nobody switches an organization's sign-in in one day. During cutover, users need to be able to sign in with the system they have today, land on their imported Seamless Auth account, and be moved onto passkeys from there. Cutover then needs to happen per group, with a way back.
Proposal
Use the existing OAuth provider support (src/services/oauthService.ts, providers configured with authorizationUrl / tokenUrl) as the bridge from the legacy identity provider:
Confirm whether today's OAuth flow links to an existing (imported) user, and on what. Linking must require a verified email from the provider, or a match on the imported externalId, never an unverified claim. Shipped in v0.16.0 (GHSA-p3fh-cq88-92h6): linking now needs a provider-verified email, and Entra links on the immutable oid
OIDC discovery and ID token validation for providers such as Entra ID, Okta and Google Workspace, if not already covered. Shipped in v0.16.0: ID token verification against the configured issuer and jwksUri. Discovery (fetching .well-known/openid-configuration) is not implemented; both values are set on the provider explicitly
Part of #334.
Problem
Nobody switches an organization's sign-in in one day. During cutover, users need to be able to sign in with the system they have today, land on their imported Seamless Auth account, and be moved onto passkeys from there. Cutover then needs to happen per group, with a way back.
Proposal
Use the existing OAuth provider support (
src/services/oauthService.ts, providers configured withauthorizationUrl/tokenUrl) as the bridge from the legacy identity provider:externalId, never an unverified claim. Shipped in v0.16.0 (GHSA-p3fh-cq88-92h6): linking now needs a provider-verified email, and Entra links on the immutableoidissuerandjwksUri. Discovery (fetching.well-known/openid-configuration) is not implemented; both values are set on the provider explicitlynextStep: 'enroll_passkey'for providers withpromptPasskeyEnrollment; handled in feat(oauth): passkey enrollment after a legacy provider sign-in seamless-auth-react#156 and the OAuth starter (feat(web): follow nextStep into passkey enrollment in the OAuth starter seamless-templates#95)PUT/DELETE /admin/organizations/:organizationId/oauth-providers/:providerId/retirement, withadmin_oauth_provider_retired/_restoredevents); feat(oauth): revoke members' sessions when a provider is retired #348 also revokes members' sessions on retirementSecurity
High-stakes path (account linking). Run a security review before merging.