From eeabe8f49b16a8ef1c3e85062dc473709ff2d732 Mon Sep 17 00:00:00 2001 From: Sten Date: Wed, 1 Jul 2026 15:47:45 +0200 Subject: [PATCH] feat(auth-sidecar): inject AUTH_OIDC_ALLOWED_RETURN_HOSTS Reads the new `policies.forteapps.io/auth-oidc-allowed-return-hosts` pod annotation into the OIDC sidecar's AUTH_OIDC_ALLOWED_RETURN_HOSTS env var (mirrors the existing cookie-domain wiring). Enables origin-preserving post-login redirects so a login that round-trips through a shared apex callback returns the user to the originating subdomain. Absent annotation => empty => unchanged path-only redirect, so all other apps injected by this policy are unaffected. Requires auth-sidecar >= v1.5.0 (Forte/auth-sidecar#24) and the matching forteapp chart annotation. Co-Authored-By: Claude Opus 4.8 (1M context) --- cluster-resources/policies/auth-sidecar-injector.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/cluster-resources/policies/auth-sidecar-injector.yaml b/cluster-resources/policies/auth-sidecar-injector.yaml index 611a365..90d2205 100644 --- a/cluster-resources/policies/auth-sidecar-injector.yaml +++ b/cluster-resources/policies/auth-sidecar-injector.yaml @@ -235,6 +235,8 @@ spec: value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-scopes\" || 'openid,profile,email' }}" - name: AUTH_OIDC_COOKIE_DOMAIN value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-cookie-domain\" || '' }}" + - name: AUTH_OIDC_ALLOWED_RETURN_HOSTS + value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-allowed-return-hosts\" || '' }}" - name: AUTH_PUBLIC_PATHS value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-public-paths\" || '/healthz' }}" - name: AUTH_OIDC_COOKIE_SECRET -- 2.52.0