feat(oidc): add auto-redirect for OIDC

add `auto_redirect_if_standalone_oidc` in `OXICLOUD_AUTH_POLICIES`
let admin decide to redirect immediately to IdP if OIDC is the only auth method enabled
This commit is contained in:
Edouard Vanbelle
2026-08-03 00:22:19 +02:00
parent b91f2fab2b
commit 5ebe2d3bae
12 changed files with 144 additions and 38 deletions
+8
View File
@@ -383,6 +383,14 @@ pub struct OidcProviderInfoDto {
/// straight after signup.
#[serde(default)]
pub require_verified_email: bool,
/// True iff the effective allowlist is `[Oidc]` AND the
/// `auto_redirect_if_standalone_oidc` policy is set. Frontend
/// uses this to decide whether to auto-redirect to the authorize
/// endpoint on login-page mount (true) or show a click-to-continue
/// button (false). Default false — the safe posture that avoids
/// redirect loops when the IdP is degraded.
#[serde(default)]
pub auto_redirect_to_oidc: bool,
}
/// Claims extracted from the validated OIDC ID token