rcourtman
2c96242487
Use stable SSO principals
...
Derive OIDC and SAML browser-session principals from provider-scoped subjects instead of mutable username or email claims.
Preserve compatibility by migrating legacy username/email RBAC assignments to the stable SSO principal when no authoritative group mapping is present, and pin the invariant in API/security contracts.
2026-05-04 00:16:31 +01:00
..
2026-05-03 23:51:54 +01:00
2026-05-01 20:28:11 +01:00
2026-04-22 01:36:46 +01:00
2026-04-23 23:04:18 +01:00
2026-05-01 21:36:28 +01:00
2026-05-01 20:28:12 +01:00
2026-05-04 00:16:31 +01:00
2026-03-18 16:06:30 +00:00
2026-05-03 23:28:26 +01:00
2026-05-03 21:43:20 +01:00
2026-04-22 05:13:01 +01:00
2026-04-28 09:33:26 +01:00
2026-03-18 16:06:30 +00:00
2026-04-23 13:48:54 +01:00
2026-05-01 22:03:22 +01:00
2026-05-03 23:28:26 +01:00
2026-03-18 16:06:30 +00:00
2026-04-23 13:48:54 +01:00
2026-05-03 13:19:51 +01:00
2026-04-11 22:46:34 +01:00
2026-03-18 16:06:30 +00:00
2026-04-25 23:01:01 +01:00
2026-04-10 12:33:57 +01:00
2026-04-01 12:21:36 +01:00
2026-04-10 12:33:57 +01:00
2026-05-03 23:58:08 +01:00
2026-05-03 21:43:20 +01:00
2026-05-01 22:26:01 +01:00
2026-03-29 11:38:35 +01:00
2026-05-01 21:36:28 +01:00
2026-04-23 13:48:54 +01:00
2026-04-30 12:24:22 +01:00
2026-04-23 13:48:54 +01:00
2026-03-18 16:06:30 +00:00
2026-04-21 22:47:23 +01:00
2026-03-18 16:06:30 +00:00
2026-04-30 14:31:14 +01:00
2026-03-18 16:06:30 +00:00
2026-04-14 11:05:10 +01:00
2026-04-11 16:47:37 +01:00
2026-03-31 18:05:55 +01:00
2026-04-30 14:31:14 +01:00
2026-05-01 20:28:11 +01:00
2026-04-22 03:51:46 +01:00
2026-03-19 03:07:56 +00:00
2026-03-31 18:05:55 +01:00
2026-05-01 21:36:28 +01:00