Reads the new `policies.forteapps.io/auth-oidc-allowed-return-hosts` pod
annotation into the OIDC sidecar's AUTH_OIDC_ALLOWED_RETURN_HOSTS env var
(mirrors the existing cookie-domain wiring). Enables origin-preserving
post-login redirects so a login that round-trips through a shared apex
callback returns the user to the originating subdomain.
Absent annotation => empty => unchanged path-only redirect, so all other
apps injected by this policy are unaffected. Requires auth-sidecar >= v1.5.0
(Forte/auth-sidecar#24) and the matching forteapp chart annotation.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adds AUTH_OIDC_COOKIE_DOMAIN to the injected OIDC sidecar, from the `policies.forteapps.io/auth-oidc-cookie-domain` annotation. Empty when unset = host-only = unchanged for every app. Pairs with forte-helm + auth-sidecar#23. Safe to merge anytime (opt-in).
---------
Co-authored-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Reviewed-on: #24
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>