Skip to content

docs: improve advanced sso page#9507

Open
wvandeun wants to merge 2 commits into
release-1.10from
docs/sso-group-mapping
Open

docs: improve advanced sso page#9507
wvandeun wants to merge 2 commits into
release-1.10from
docs/sso-group-mapping

Conversation

@wvandeun

@wvandeun wvandeun commented Jun 8, 2026

Copy link
Copy Markdown
Contributor

Summary by cubic

Clarifies and restructures Advanced SSO docs for group mapping: map to existing groups, auto-create from claims (regex filters incl. multiple patterns, JSON-array env var, per-login cap, audit events, provenance; invalid regex blocks startup), and a default-group fallback (SSO logins only).
Adds IdP group-claim setup, log examples, a membership-resolution overview (behavior with/without auto-creation), and sets toc_max_heading_level: 4.

Written for commit 32b2e74. Summary will update on new commits.

Review in cubic

@github-actions github-actions Bot added the type/documentation Improvements or additions to documentation label Jun 8, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 1 file

Confidence score: 4/5

  • This PR looks safe to merge overall, but there is a minor documentation accuracy issue in docs/docs/deploy-manage/user-management/sso/advanced-sso.mdx.
  • The summary currently states all three group-mapping approaches require IdP group claims, which conflicts with the documented default-group path intended for setups without group claims.
  • Because the issue is low severity (3/10) and limited to wording, risk is minimal, but it could still mislead SSO configuration decisions for readers.
  • Pay close attention to docs/docs/deploy-manage/user-management/sso/advanced-sso.mdx - ensure the summary distinguishes the no-group-claims default-group flow from claim-dependent mappings.

Shadow auto-approve: would not auto-approve because issues were found.

Re-trigger cubic

Comment thread docs/docs/deploy-manage/user-management/sso/advanced-sso.mdx
Local username/password logins never use the default group; only the SSO
sign-in path reads sso_user_default_group.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 1 file (changes from recent commits).

Shadow auto-approve: would auto-approve. This PR only updates documentation for the Advanced SSO page, restructuring explanations and adding examples without any changes to source code, configuration, or business logic, so the risk of breakage is extremely low.

Re-trigger cubic

@wvandeun wvandeun marked this pull request as ready for review June 9, 2026 07:35
@wvandeun wvandeun requested review from a team as code owners June 9, 2026 07:35
@wvandeun wvandeun requested review from a team and removed request for a team June 9, 2026 07:35
@wvandeun wvandeun self-assigned this Jun 9, 2026
@wvandeun wvandeun changed the base branch from develop to release-1.10 June 9, 2026 13:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type/documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant