inject-sidecar-oidc now maps the policies.forteapps.io/auth-oidc-allowed-return-hosts pod annotation into the sidecar's AUTH_OIDC_ALLOWED_RETURN_HOSTS env var (mirrors the existing AUTH_OIDC_COOKIE_DOMAIN wiring).
Why
Enables origin-preserving post-login redirects so a login that round-trips through a shared apex callback returns the user to the originating subdomain — fixing cold-login on <slug>.drop.forteapps.net landing on the apex admin page.
Safety
Absent annotation → '' → unchanged path-only redirect. Every other app injected by this ClusterPolicy is unaffected.
Activation chain (all required)
Forte/auth-sidecar#24 — sidecar support (≥ v1.5.0)
Forte/forte-helmfix/oidc-allowed-return-hosts — chart emits the annotation
this PR — injector reads annotation → env
Forte/helm-prod-valuesfeat/forte-drop-allowed-return-hosts — sets the value
## What
`inject-sidecar-oidc` now maps the `policies.forteapps.io/auth-oidc-allowed-return-hosts` pod annotation into the sidecar's `AUTH_OIDC_ALLOWED_RETURN_HOSTS` env var (mirrors the existing `AUTH_OIDC_COOKIE_DOMAIN` wiring).
## Why
Enables origin-preserving post-login redirects so a login that round-trips through a shared apex callback returns the user to the originating subdomain — fixing cold-login on `<slug>.drop.forteapps.net` landing on the apex admin page.
## Safety
Absent annotation → `''` → unchanged path-only redirect. Every other app injected by this ClusterPolicy is unaffected.
## Activation chain (all required)
1. `Forte/auth-sidecar#24` — sidecar support (≥ v1.5.0)
2. `Forte/forte-helm` `fix/oidc-allowed-return-hosts` — chart emits the annotation
3. **this PR** — injector reads annotation → env
4. `Forte/helm-prod-values` `feat/forte-drop-allowed-return-hosts` — sets the value
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Reads the new `policies.forteapps.io/auth-oidc-allowed-return-hosts` pod
annotation into the OIDC sidecar's AUTH_OIDC_ALLOWED_RETURN_HOSTS env var
(mirrors the existing cookie-domain wiring). Enables origin-preserving
post-login redirects so a login that round-trips through a shared apex
callback returns the user to the originating subdomain.
Absent annotation => empty => unchanged path-only redirect, so all other
apps injected by this policy are unaffected. Requires auth-sidecar >= v1.5.0
(Forte/auth-sidecar#24) and the matching forteapp chart annotation.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
jorgen.stensrud
requested review from danijel.simeunovic 2026-07-01 13:49:14 +00:00
jorgen.stensrud
requested review from edvard.unsvag 2026-07-01 13:49:14 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What
inject-sidecar-oidcnow maps thepolicies.forteapps.io/auth-oidc-allowed-return-hostspod annotation into the sidecar'sAUTH_OIDC_ALLOWED_RETURN_HOSTSenv var (mirrors the existingAUTH_OIDC_COOKIE_DOMAINwiring).Why
Enables origin-preserving post-login redirects so a login that round-trips through a shared apex callback returns the user to the originating subdomain — fixing cold-login on
<slug>.drop.forteapps.netlanding on the apex admin page.Safety
Absent annotation →
''→ unchanged path-only redirect. Every other app injected by this ClusterPolicy is unaffected.Activation chain (all required)
Forte/auth-sidecar#24— sidecar support (≥ v1.5.0)Forte/forte-helmfix/oidc-allowed-return-hosts— chart emits the annotationForte/helm-prod-valuesfeat/forte-drop-allowed-return-hosts— sets the value🤖 Generated with Claude Code