Repository navigation
Auth/PM-42167 - SSO - Add Staged Org User Support #8228
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
JaredSnider-Bitwarden
merged 11 commits into
main
from
auth/pm-42167/sso-add-staged-org-users-support
Aug 25, 2026
Merged
Changes from all commits
Commits
Show all changes
11 commits
Select commit
Hold shift + click to select a range
250b8fe
PM-42167 - Auth - Add SSO support for Staged organization users
JaredSnider-Bitwarden e9e657c
PM-42167 - Auth - Bump OrganizationUser.RevisionDate on Scenario 3 mu…
JaredSnider-Bitwarden 4561078
PM-42167 - Auth - Add SSO Case A (existing BW user) promotion for Sta…
JaredSnider-Bitwarden 955aaa3
PM-42167 - Auth - Add dedicated error code for SSO Staged OrgUser pro…
JaredSnider-Bitwarden 3575878
PM-42167 - Auth - Remove event log from SSO Staged OrgUser promotion
JaredSnider-Bitwarden bef1c49
PM-42167 - Auth - Trim PromoteStagedOrgUserAndSendInviteAsync doc com…
JaredSnider-Bitwarden ef584fe
PM-42167 - Auth - Hoist SSO seat check before user creation for Stage…
JaredSnider-Bitwarden 0b986b9
PM-42167 - Reject Key Connector SSO login against Staged OrgUser row …
JaredSnider-Bitwarden 228a10d
Merge branch 'main' into auth/pm-42167/sso-add-staged-org-users-support
JaredSnider-Bitwarden 1d2960f
PM-42167 - Auth - Roll back SSO Staged OrgUser promotion on invite-se…
JaredSnider-Bitwarden 4b6946e
Merge branch 'main' into auth/pm-42167/sso-add-staged-org-users-support
JaredSnider-Bitwarden File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
29 changes: 29 additions & 0 deletions
29
...rden_license/src/Sso/Exceptions/SsoAuthnStagedOrgUserRequiresInviteAcceptanceException.cs
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,29 @@ | ||
| namespace Bit.Sso.Exceptions; | ||
|
|
||
| /// <summary> | ||
| /// Thrown when SSO authentication is refused because the existing Bitwarden user | ||
| /// matches an <see cref="Bit.Core.Enums.OrganizationUserStatusType.Staged"/> | ||
| /// OrganizationUser row that was just promoted to | ||
| /// <see cref="Bit.Core.Enums.OrganizationUserStatusType.Invited"/> as part of this | ||
| /// SSO attempt. A fresh invite email has been sent; the user must accept it (via | ||
| /// master password login) before SSO can proceed. | ||
| /// | ||
| /// Distinct from <see cref="SsoAuthnRequiresInviteAcceptanceException"/> so the | ||
| /// client can tell the user to check their email for a newly-sent invite rather | ||
| /// than referencing an invite they should already have received. | ||
| /// </summary> | ||
| public class SsoAuthnStagedOrgUserRequiresInviteAcceptanceException : Exception | ||
| { | ||
| public Guid OrganizationId { get; } | ||
| public string OrganizationDisplayName { get; } | ||
| public string UserEmail { get; } | ||
|
|
||
| public SsoAuthnStagedOrgUserRequiresInviteAcceptanceException( | ||
| Guid organizationId, string organizationDisplayName, string userEmail) | ||
| : base($"Staged OrganizationUser promoted to Invited and direct org invite email sent; invite acceptance required before SSO for org '{organizationDisplayName}'.") | ||
| { | ||
| OrganizationId = organizationId; | ||
| OrganizationDisplayName = organizationDisplayName; | ||
| UserEmail = userEmail; | ||
| } | ||
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
33 changes: 33 additions & 0 deletions
33
...e/test/SSO.Test/Exceptions/SsoAuthnStagedOrgUserRequiresInviteAcceptanceExceptionTests.cs
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,33 @@ | ||
| using Bit.Sso.Exceptions; | ||
|
|
||
| namespace Bit.SSO.Test.Exceptions; | ||
|
|
||
| public class SsoAuthnStagedOrgUserRequiresInviteAcceptanceExceptionTests | ||
| { | ||
| [Fact] | ||
| public void Constructor_AssignsProperties() | ||
| { | ||
| var orgId = Guid.NewGuid(); | ||
| var ex = new SsoAuthnStagedOrgUserRequiresInviteAcceptanceException( | ||
| organizationId: orgId, | ||
| organizationDisplayName: "Acme Corp", | ||
| userEmail: "staged@example.com"); | ||
|
|
||
| Assert.Equal(orgId, ex.OrganizationId); | ||
| Assert.Equal("Acme Corp", ex.OrganizationDisplayName); | ||
| Assert.Equal("staged@example.com", ex.UserEmail); | ||
| } | ||
|
|
||
| [Fact] | ||
| public void Constructor_SetsDescriptiveMessage() | ||
| { | ||
| var ex = new SsoAuthnStagedOrgUserRequiresInviteAcceptanceException( | ||
| organizationId: Guid.NewGuid(), | ||
| organizationDisplayName: "Acme Corp", | ||
| userEmail: "staged@example.com"); | ||
|
|
||
| // The message is used by server logs/error pages, not the redirect URL, | ||
| // so we just sanity-check it includes the org name for diagnosability. | ||
| Assert.Contains("Acme Corp", ex.Message); | ||
| } | ||
| } |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.