Skip to content

reference: add JWT identity providers entries - #2365

Open
wasaga wants to merge 1 commit into
mainfrom
wasaga/jwt-providers-docs
Open

wasaga wants to merge 1 commit into
mainfrom
wasaga/jwt-providers-docs

Conversation

@wasaga

@wasaga wasaga commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

updates reference.json for identity_providers (global) and the per-route allowlist

The reference pages for `identity_providers` (global) and the per-route
allowlist existed, but neither had an entry in reference.json, so the
Console — which builds its help links from that file — rendered no help
icon for either field.

Add both entries, and rename routes/identity-providers.mdx to match its
frontmatter id. Docusaurus derives the URL from the id, not the filename,
so the file-path form used by the sibling pass-identity-headers entry
404s (/docs/reference/routes/pass-identity-headers is a 404 today, while
.../pass-identity-headers-per-route serves). Matching the filename to the
id keeps the disk path and the served URL in agreement; the live URL is
unchanged, so existing links to the page still resolve.

Also correct two statements on the per-route page. It claimed every name
must exist in the global identity_providers map, and that setting the
field on a non-jwt route is a configuration error that stops Pomerium
from starting. Neither holds: validateIdentityProviders only validates
the providers map itself and never cross-checks route references, so both
configurations pass validation. An undeclared name simply never matches a
token's issuer. Document that, and the related sharp edge that an empty
list accepts any configured provider — so emptying a list widens a route
rather than closing it.
@netlify

netlify Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for pomerium-docs ready!

Name Link
🔨 Latest commit 89f3994
🔍 Latest deploy log https://app.netlify.com/projects/pomerium-docs/deploys/6ab161be69f6a1000853c75a
😎 Deploy Preview https://deploy-preview-2365--pomerium-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@wasaga
wasaga marked this pull request as ready for review September 21, 2026 16:59
@wasaga
wasaga requested a review from a team as a code owner September 21, 2026 16:59
@wasaga
wasaga requested review from a team, calebdoxsey and nickytonline and removed request for a team September 21, 2026 16:59
@greptile-apps

greptile-apps Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

The PR is generally safe to merge, but the missing redirect and contradictory non-JWT guidance should be corrected to avoid broken external links and ambiguous operational documentation.

Fix All in Claude CodeFindings

  1. P2 Non-JWT Guidance Conflicts ▶

Summary

This PR adds global and per-route JWT identity-provider entries to the configuration reference and renames the per-route reference page for clarity.

  • Adds searchable reference metadata for both identity-provider settings.
  • Clarifies runtime matching and empty-allowlist semantics.
  • Updates the per-route page URL, but does not preserve the former URL with a redirect.
  • Introduces conflicting guidance about behavior on non-JWT routes.

Reviews (1) · Last reviewed commit: "reference: add JWT identity providers en..."

Comment thread content/docs/reference/routes/identity-providers-per-route.mdx
@greptile-apps

greptile-apps Bot commented Sep 21, 2026

Copy link
Copy Markdown

Comments Outside Diff

These findings sit on lines the diff does not cover, so they could not be posted inline. Each one leaves this list once its file changes.

  • P2 Old URL Has No Redirect content/docs/reference/routes/identity-providers-per-route.mdx:4 ▶

    Renaming this page changes its published URL from /docs/reference/routes/identity-providers to /docs/reference/routes/identity-providers-per-route, and static/_redirects has no redirect for the former route. If anyone follows an existing bookmark, indexed result, or external link, the old URL will return 404. Please add a permanent redirect.

    A red test proving the redirect is missing:

    import assert from 'node:assert/strict';
    import fs from 'node:fs';
    
    const redirects = fs.readFileSync('static/_redirects', 'utf8');
    assert.match(
      redirects,
      /^\/docs\/reference\/routes\/identity-providers\s+\/docs\/reference\/routes\/identity-providers-per-route\s+301$/m,
      'the former published route must redirect to the renamed page',
    );

    This currently fails because static/_redirects contains no entry for the former route.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant