Skip to content

feat(sso): open Sim from an identity provider's app dashboard - #7865

Merged
waleedlatif1 merged 6 commits into
stagingfrom
feat/sso-idp-initiated-login
Sep 15, 2026
Merged

waleedlatif1 merged 6 commits into
stagingfrom
feat/sso-idp-initiated-login

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Sep 15, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Adds OpenID Connect third-party initiated login, so people can open Sim from an identity provider's app dashboard (e.g. an Okta tile) without typing an email
  • New initiate login URL: GET /sso/launch/[providerId], a server route that redirects straight to the identity provider
    • It carries no query of its own, so the ?iss= the dashboard appends always parses cleanly
    • Sign-in starts only for a domain-verified OIDC provider configured with that issuer, or one on the same host (Okta sends the organization URL even for a provider registered against a custom authorization server under it)
    • It forwards Better Auth's signed state cookie with the redirect, the same way the OAuth2 authorize route does
    • Admitted per IP like /api/auth/sso/resolve
  • Someone already signed in goes straight to the app, so a crafted launch link can't replace an existing session
  • Anything else — unknown issuer, provider this deployment doesn't serve, refused sign-in — falls back to the provider's existing sign-in link (/sso?provider=…), which asks for an email
  • OIDC providers show an Initiate login URL row with a copy button on their settings page, next to Callback URL. The existing Test sign-in link row is unchanged
  • The /sso page and SSO form are untouched
  • Docs: Okta guide covers the dashboard tile settings, the new URL is described under how sign-in works, and <your-sim-domain> is clarified for Sim Cloud
  • Known tradeoff: like any third-party initiated OIDC login, a signed-out visitor who opens a launch link for someone else's verified provider starts sign-in there. That needs an attacker-owned verified domain and IdP, and signed-in sessions are protected

Type of Change

  • New feature

Testing

  • Route tests: redirect plus state cookie, already signed in, missing or mismatched issuer, refused sign-in, rate limited, SSO disabled, and that the plugin's appended ?error= can't corrupt the retry link
  • Issuer tests: exact match, trailing slash, custom authorization server under the same host, other issuers, non-URL values, unknown/unverified/SAML providers
  • Settings row test: OIDC only, no query in the URL
  • Mutation-checked: the issuer and auto-start tests fail when those lines are removed
  • lint, check:audits, check:api-validation:strict, docs-manifest:check, type-check pass

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Sep 15, 2026 11:38pm UTC

Request Review

@greptile-apps

greptile-apps Bot commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The PR appears safe to merge with no outstanding correctness, security, or repository-rule issues.

Summary

Adds third-party-initiated OIDC login so users can launch Sim from an identity provider dashboard.

  • Introduces a rate-limited launch route that validates the provider and issuer before starting SSO.
  • Preserves authenticated sessions and forwards Better Auth’s signed state cookie.
  • Exposes the initiate-login URL in OIDC provider settings.
  • Adds route, issuer-validation, and settings coverage, plus Okta setup documentation.
  • Since the previous review, normalizes caught values with toError before logging.
Diagram
sequenceDiagram
    participant User
    participant IdP
    participant Launch as Sim launch route
    participant DB as SSO provider store
    participant Auth as Better Auth

    User->>IdP: Open application tile
    IdP->>Launch: "GET /sso/launch/{providerId}?iss={issuer}"
    Launch->>Launch: Check existing session
    alt Already signed in
        Launch-->>User: Redirect to /home
    else Signed out
        Launch->>Launch: Apply per-IP rate limit
        Launch->>DB: Resolve verified OIDC provider
        DB-->>Launch: Configured issuer
        Launch->>Launch: Compare issuer or origin
        alt Issuer accepted
            Launch->>Auth: Start provider SSO
            Auth-->>Launch: Authorization URL and state cookie
            Launch-->>User: Redirect to IdP with state cookie
        else Invalid or unavailable
            Launch-->>User: Redirect to provider email sign-in
        end
    end
Loading

Reviews (5) · Last reviewed commit: "chore(sso): normalize the caught error w..."

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 9 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

Comment thread apps/sim/app/(auth)/sso/launch/[providerId]/route.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 7 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/app/(auth)/sso/launch/[providerId]/route.ts
Comment thread apps/sim/app/(auth)/sso/launch/[providerId]/route.ts
Comment thread apps/sim/app/(auth)/sso/launch/[providerId]/route.ts Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

Comment thread apps/sim/lib/auth/sso/idp-initiated-login.ts
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

Comment thread apps/sim/app/(auth)/sso/launch/[providerId]/route.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 7 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 7 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit 5bca037 into staging Sep 15, 2026
25 checks passed
@waleedlatif1
waleedlatif1 deleted the feat/sso-idp-initiated-login branch September 15, 2026 23:40

This branch was previously deployed

1 inactive deployment
Preview — be4db0be Deployed Sep 15, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant