Skip to content

feat(api): expose credential sharing and SSO administration - #8770

Merged
waleedlatif1 merged 5 commits into
stagingfrom
codex/credential-sharing-sso-api
Oct 8, 2026
Merged

waleedlatif1 merged 5 commits into
stagingfrom
codex/credential-sharing-sso-api

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Expose credential member management, organization SSO providers and policy, and verified-domain administration through 14 public API, CLI, and MCP operations backed by shared authorized application use cases.
  • Keep SSO configuration and domain trust in one transaction, serialize provider and domain changes, recheck current administrator access, enforce domain limits under concurrency, and preserve secret redaction, DNS ownership checks, existing OIDC/SAML settings, and SSO audit events across caller surfaces.
  • Align CLI pagination, bodyless actions, and bounded secret-file input, with regenerated OpenAPI, operation metadata, and documentation.

Type of Change

  • New feature
  • Bug fix

Testing

  • Root lint, all 26 workspace type checks, all 58 repository audits, docs manifest, and block registry checks.
  • Repository scripts, workspace suites, and both application test shards run in the existing CI jobs; local focused suites also passed.
  • 127 integration checks against disposable PostgreSQL and Redis, including real CLI-to-HTTP requests, persisted security audit events, and concurrency regressions; JSON report produced. Regression guards demonstrated failures before their fixes.
  • 266 focused application tests and all 474 CLI tests.
  • Regenerated OpenAPI, CLI, MCP, route tables, and CLI documentation. Semantic comparison confirms existing endpoint definitions are unchanged.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 8, 2026 3:47am UTC

Request Review

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

We detected this is a high-risk PR and are running a free ultrareview. An ultrareview is a deeper, multi-pass review that catches hard-to-find bugs a standard review can miss. We'll post the findings when it completes.

This PR appears to change authentication, authorization, or input validation, where a missed bug can expose data or grant the wrong access, so a deeper multi-pass review is worth running.

Want an ultrareview on every high-risk PR? Set up automated ultrareviews.

@greptile-apps

greptile-apps Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Critical risk] Adds new API endpoints for SSO and credential sharing administration.

This PR appears safe to merge; no new actionable issue remains.

What we checked:

  • Provider reads hide secrets: publicConfig masks clientSecret and copies only selected fields from nested SAML metadata.
  • Provider saves recheck access: saveSsoProvider checks administrator access again inside the transaction, after acquiring the organization and provider locks.

Summary

Adds 14 public API, CLI, and MCP operations for credential sharing, SSO providers and policy, and verified domains.

  • Shares authorized application use cases across the existing settings routes and new public routes.
  • Saves provider configuration and domain trust together, with current administrator checks and serialized writes.
  • Adds cursor pagination, bounded secret-file input, and regenerated API documentation.
  • The three earlier, unnumbered findings are addressed: bodyless actions accept missing JSON, UserInfo clearing reaches persistence, and admission acquires organization locks before the provider-row lock.
  • No new actionable issues were established. Tests were inspected, not run.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  CLI[CLI] --> API[Public v2 routes]
  MCP[MCP] --> API
  UI[Settings routes] --> UseCase[Shared application use cases]
  API --> UseCase
  UseCase --> Access[Check current access]
  Access --> Write[Lock and save changes]
  Write --> DB[(PostgreSQL)]
  Write --> Audit[Record the acting user]
Loading

Reviews (5) · Last reviewed commit: "fix(auth): preserve SSO audit events acr..." · Reviewed by Greptile

Comment thread apps/sim/lib/api/contracts/v2/sso.ts Outdated
Comment thread apps/sim/lib/auth/sso/provider-repository.ts

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We detected this is a high-risk PR and ran a free ultrareview. An ultrareview is a deeper, multi-pass review that catches hard-to-find bugs a standard review can miss.

This PR appears to change authentication, authorization, or input validation, where a missed bug can expose data or grant the wrong access, so a deeper multi-pass review is worth running.

Want an ultrareview on every high-risk PR? Set up automated ultrareviews.

All reported issues were addressed across 68 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread packages/sim-cli/src/contract/commands.ts
Comment thread apps/sim/lib/api/server/sso-presenters.ts Outdated
Comment thread apps/sim/lib/auth/sso/application/provider-registration.ts
Comment thread apps/sim/lib/auth/sso/application/provider-registration.ts
Comment thread apps/sim/lib/auth/sso/provider-adapter.ts Outdated
Comment thread apps/sim/lib/api/contracts/auth.ts Outdated
Comment thread apps/sim/lib/api/contracts/v2/sso.ts Outdated
Comment thread apps/sim/lib/api/contracts/v2/openapi/credential-members.ts Outdated
@waleedlatif1
waleedlatif1 force-pushed the codex/credential-sharing-sso-api branch from a76af45 to c1663ca Compare October 8, 2026 02:39
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 87 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/auth/sso/registration-input.ts Outdated
Comment thread apps/sim/lib/auth/sso/provider-repository.ts
Comment thread apps/sim/lib/auth/sso/application/provider-settings.integration.ts
Comment thread apps/sim/lib/auth/sim-auth-adapter.ts Outdated
Comment thread apps/sim/lib/auth/sso/provider-repository.ts
Comment thread apps/sim/lib/api/contracts/v2/openapi/credential-members.ts Outdated
Comment thread apps/sim/lib/auth/sso/application/provider-registration.ts
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 91 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/api/contracts/v2/openapi/credential-members.ts Outdated
Comment thread apps/sim/lib/auth/sso/registration-input.ts Outdated
Comment thread apps/sim/lib/auth/sso/registration-input.ts Outdated
Comment thread apps/sim/lib/auth/sso/registration-input.ts Outdated
Comment thread apps/sim/lib/api/contracts/v2/openapi/credential-members.ts Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 92 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 force-pushed the codex/credential-sharing-sso-api branch from 58bb13d to 592f969 Compare October 8, 2026 03:42
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 95 files

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/auth/sso/application/provider-settings.ts
@waleedlatif1
waleedlatif1 merged commit 684b228 into staging Oct 8, 2026
47 of 48 checks passed
@waleedlatif1
waleedlatif1 deleted the codex/credential-sharing-sso-api branch October 8, 2026 04:21

This branch was successfully deployed

1 active deployment
Preview — 592f969a Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant