Skip to content

feat(providers): allow a NyxID-managed LinkedIn OAuth app - #1771

Merged
ctkm-aelf merged 1 commit into
mainfrom
linkedin-oauth-setup
Oct 5, 2026
Merged

ctkm-aelf merged 1 commit into
mainfrom
linkedin-oauth-setup

Conversation

@ctkm-aelf

Copy link
Copy Markdown
Collaborator

Summary

  • Remove linkedin from SEEDED_USER_CREDENTIAL_OAUTH_PROVIDER_SLUGS, so an admin-provisioned shared LinkedIn app (credential_mode both/admin) is no longer reset to user on every startup. This matches Twitter: the seed stays BYO-only and ops opt in.
  • Add a platform_scope_allowlist entry for linkedin (openid profile email w_member_social), the products the shared app currently has (OIDC and Share on LinkedIn). Page, ads and hiring scopes are rejected on the shared app and still need a BYO app until LinkedIn approves those products.

Admin setup after deploy

Providers → Manage Providers → LinkedIn → Edit: set Credential Mode to Admin or User, enter the client ID and secret, and set the default scopes to openid profile email w_member_social. The LinkedIn app must list {BASE_URL}/api/v1/providers/callback as an authorized redirect URL.

Test plan

  • cargo fmt --all -- --check
  • scope_catalog::tests::linkedin_platform_allowlist_matches_approved_products (new)
  • seed_does_not_revert_ops_patched_both, now covering linkedin
  • seed_keeps_google_github_both_across_restarts and the existing platform allowlist tests
  • CI Pipeline

🤖 Generated with Claude Code

LinkedIn was in the startup migration that forces seeded social providers
back to credential_mode "user", so an admin-provisioned shared app
("both"/"admin") reverted on every restart. Exclude it, matching Twitter:
the seed stays BYO-only and ops opt in by setting the provider's client
credentials and mode.

Add a platform scope allowlist for the shared LinkedIn app covering the
products it currently holds (OIDC and Share on LinkedIn). Page, ads and
hiring scopes still require a BYO app until those products are approved.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

📊 Code coverage

Component Lines Threshold Status Δ vs base
Backend (nyxid) 86.95% 73% ✅ — 0.00

Gate: line coverage must stay at or above the threshold. Ratchet plan (W21): Backend → 55%, CLI → 50%, Frontend → 30% by quarter end.

@ctkm-aelf
ctkm-aelf merged commit 3b75583 into main Oct 5, 2026
37 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant