* fix(oidc): ignore groups without a matching policy at login OIDC login failed with "OIDC policy mapping did not resolve to current policies" whenever any mapped group lacked a policy of the same name. Directory-backed providers such as Active Directory always emit groups like `DOMAIN\Domain Users` that can never be mapped, so group-based authorization was impossible there. Keep only policy names that resolve to an existing policy and are valid in session claims, and reject the login only when none remain. The signed `policy` claim still lists only resolved names, so request-time evaluation and site replication receivers keep their invariant. Refs #8163 * fix(oidc): only ignore unmapped groups-claim values Limit the relaxed resolution to policy names derived solely from the groups claim. Names from ROLE_POLICY, a dedicated CLAIM_NAME claim, or an explicit IAM policy mapping must still all resolve. Reject the login when a mapped name refers to an existing policy whose name is not allowed in session claims: dropping it could remove an explicit Deny and broaden access. Claim-unsafe names are only checked against the in-memory policy cache and never passed to storage-backed policy loading. Refs #8163 * docs(oidc): document ignorable roles claim values and cover wiring Roles claim values are merged into the canonical groups, so values without a matching policy are ignored like groups-claim values. This covers built-in provider roles such as Keycloak's `offline_access`. Document that in the field and method docs and in the provider requirements, and pin it with a test. Assert that the OIDC authorization carries the group claim policies so a regression in the wiring cannot silently disable the relaxation. Refs #8163 * fix(oidc): ignore group policies only after confirmed absence merge_policies drops names whose load fails, so a storage or decode error for an uncached group policy was indistinguishable from a missing one. The group name was then ignored and the session signed without it, which could remove an existing Deny that request-time checks cannot restore. Add IamSys::policy_exists, which consults the cache and then storage and reports false only for NoSuchPolicy while returning every other error. The OIDC binding now ignores a group-derived name only after a confirmed absence and rejects the login when a lookup fails. Refs #8163 --------- Co-authored-by: cxymds <cxymds@gmail.com> Co-authored-by: Chris <anzhengchao@gmail.com>
Documentation
Use the focused indexes rather than treating this directory as an unordered collection:
Operations
-
Architecture guard troubleshooting — diagnose repository guard failures.
-
Logging governance — broad event audits, migrations, and guardrail changes.
-
Multipart upload memory diagnosis — allocator attribution, Docker reproduction and sustained upload checks.
For the logical per-operation io_uring read cap, see io_uring read chunk size.
For bounded local read-backend startup and cancellation, see io_uring backend initialization.
For legacy protection assessment and bounded protected copies, see Object integrity inventory, audit, and migration.
Operational runbooks live under operations/. Replication
operators should start with:
| Runbook | Use it for |
|---|---|
| Site replication operations | Health fields, pending operations, outage recovery, re-pair admission, IAM/SSE boundaries, and upgrades. |
| Replication target check | Validating an S3 destination and version fidelity before enabling replication. |
| Replication object size limits | Multipart routing, large-object limits, and retry characteristics. |
| Replication outbound transport | Integrity headers, generic target behavior, and transport knobs. |
For the erasure-coded cluster lifecycle (planning, parity and EC:0,
expansion, rebalance, decommission, heal, drive replacement, restart
recovery, and the rc CLI mapping), start with
Cluster and erasure-coding lifecycle operations.
For concurrent bucket creation and deletion, see Bucket operation admission.
For persisted administrator bucket tasks and bucket recreation, see Bucket heal recovery.
For disk replacement across VM restarts and schema 5/6 maintenance migration, see Replacement generation recovery.
For historical GET timeouts during PUT or Heal, see Object lock contention diagnostics.
Other runbooks remain grouped by filename in operations/;
architecture pages link to the relevant runbook where a cross-boundary
procedure is required.
For storage dashboards, see Storage metrics and observer selection: drive ownership, snapshot freshness, counter queries, and rolling upgrades.
For optional shard commitments, see Independent shard integrity rollout: activation, legacy repair results, multipart mode changes, and rollback limits.
For crates.io publication of workspace crates, see Workspace Cargo Publish: dependency ordering, dry-run, publish, and failure handling.