chore: remove deprecated env-var identity provider configuration - #1297

Merged
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars
Jun 10, 2026
Merged

chore: remove deprecated env-var identity provider configuration#1297
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Summary

Removes support for configuring identity providers via the deprecated AUTH_EE_* environment variables for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID. These providers must now be configured through the identityProviders section of the config file, which is already a complete replacement (every one of these providers is supported there).

GCP IAP is intentionally unaffectedAUTH_EE_GCP_IAP_ENABLED and AUTH_EE_GCP_IAP_AUDIENCE remain supported (they're also read in layout.tsx / onboard/page.tsx to drive the IAP bridge sign-in). AUTH_EE_ALLOW_EMAIL_ACCOUNT_LINKING is also untouched (it's a behavioral flag, not a provider credential).

Changes

  • packages/web/src/ee/features/sso/sso.ts — removed the deprecated env-var provider blocks from the identityProviders.length == 0 path (kept GCP IAP).
  • packages/backend/src/ee/tokenRefresh.ts — removed getDeprecatedEnvCredentials and its fallback in refreshOAuthToken; token refresh now relies solely on config-file provider credentials.
  • packages/shared/src/env.server.ts — removed the deprecated AUTH_EE_{GITHUB,GITLAB,GOOGLE,OKTA,KEYCLOAK,MICROSOFT_ENTRA_ID}_* env var declarations.

Breaking change

Deployments configuring any of the six providers via AUTH_EE_* environment variables must migrate to the identityProviders config-file section. No functionality is lost — only the configuration mechanism changes.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Breaking Changes

    • Removed support for configuring GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID via deprecated AUTH_EE_* environment variables. These providers must be configured in the config file’s identityProviders section; providers still configured only via env vars will stop appearing on the login screen. GCP IAP env vars remain supported.
  • Documentation

    • Upgrade guide updated with migration steps, examples, and a GitHub config example.

Removes support for configuring GitHub, GitLab, Google, Okta, Keycloak, and
Microsoft Entra ID identity providers via the deprecated AUTH_EE_*_CLIENT_ID/
SECRET/etc. environment variables. These providers must now be defined through
the identityProviders section of the config file. GCP IAP env vars
(AUTH_EE_GCP_IAP_ENABLED / AUTH_EE_GCP_IAP_AUDIENCE) are unaffected.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a150cfa-3476-4776-a4c7-88ca95465523

📥 Commits

Reviewing files that changed from the base of the PR and between 89dbcd5 and 0cc3bb8.

📒 Files selected for processing (1)
  • CHANGELOG.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • CHANGELOG.md

Walkthrough

This PR removes deprecated AUTH_EE_* identity-provider environment variables from the server schema, removes env-var fallback from token refresh and SSO initialization, and adds a breaking-change note and upgrade guidance directing users to the config file identityProviders section.

Changes

Remove deprecated OAuth environment variable fallback

Layer / File(s)Summary
Environment schema removal
packages/shared/src/env.server.ts
The deprecated AUTH_EE_* identity provider environment variable block is removed from the server schema, eliminating all legacy OAuth provider credential definitions for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID.
Token refresh and SSO cleanup
packages/backend/src/ee/tokenRefresh.ts, packages/web/src/ee/features/sso/sso.ts
The getDeprecatedEnvCredentials helper is removed and refreshOAuthToken now logs an error and returns null instead of falling back to deprecated env vars when no provider config exists; SSO initialization no longer constructs providers from env.AUTH_EE_* variables when config providers are empty.
Changelog and upgrade guide updates
CHANGELOG.md, docs/docs/upgrade/v4-to-v5-guide.mdx
A breaking-change note documents the removal of AUTH_EE_* environment variable support and the upgrade guide adds migration steps and examples to move provider configuration into the config file identityProviders array.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#841: Directly modifies the token refresh back-compat flow by adding the deprecated AUTH_EE_* env-variable fallback that this PR removes.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: removal of deprecated environment variable-based identity provider configuration.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/remove-deprecated-sso-env-vars

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 3 commits June 9, 2026 20:49
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/ee/tokenRefresh.ts (1)

52-62: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Update docstring to remove outdated reference to deprecated env vars.

Line 57 still mentions that token refresh attempts use "client credentials from the config file (or deprecated env vars)." Since this PR removes the deprecated env-var fallback, the docstring should be updated.

📝 Proposed fix
 /**
* Ensures the OAuth access token for a given account is fresh.
*
* - If the token is not expired (or has no expiry), decrypts and returns it as-is.
* - If the token is expired or near expiry, attempts a refresh using the OAuth
- * client credentials from the config file (or deprecated env vars).+ * client credentials from the config file.
* - On successful refresh: persists the new tokens to the DB, clears any
* tokenRefreshErrorMessage, and returns the fresh access token.
* - On failure: sets tokenRefreshErrorMessage on the account and throws, so
* the calling job fails with a clear error.
*/
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/ee/tokenRefresh.ts` around lines 52 - 62, Update the top
docstring in tokenRefresh.ts to remove the outdated mention of deprecated env
vars: change the line that currently reads that refresh attempts use "client
credentials from the config file (or deprecated env vars)" to state they use
OAuth client credentials from the config file only; ensure any other bullets in
the same comment no longer reference deprecated env vars so the docstring
accurately reflects the removed fallback.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In `@packages/backend/src/ee/tokenRefresh.ts`:
- Around line 52-62: Update the top docstring in tokenRefresh.ts to remove the
outdated mention of deprecated env vars: change the line that currently reads
that refresh attempts use "client credentials from the config file (or
deprecated env vars)" to state they use OAuth client credentials from the config
file only; ensure any other bullets in the same comment no longer reference
deprecated env vars so the docstring accurately reflects the removed fallback.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 14ff19a4-9283-4e79-9b87-a8c834bd0b71

📥 Commits

Reviewing files that changed from the base of the PR and between cfab0cf and 014d1b4.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/tokenRefresh.ts
  • packages/shared/src/env.server.ts
  • packages/web/src/ee/features/sso/sso.ts
💤 Files with no reviewable changes (2)
  • packages/web/src/ee/features/sso/sso.ts
  • packages/shared/src/env.server.ts

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
docs/docs/upgrade/v4-to-v5-guide.mdx (1)

186-186: ⚡ Quick win

Break this paragraph into shorter chunks.

This paragraph contains 5 sentences. As per coding guidelines, documentation should prefer short paragraphs (1-3 sentences) to improve readability. Consider breaking this into 2-3 shorter paragraphs to align with the guideline.

♻️ Suggested restructuring
-In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file. Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen. This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.+In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file.++Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen.++This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/docs/upgrade/v4-to-v5-guide.mdx` at line 186, The paragraph about
deprecation of AUTH_EE_* env vars should be split into two or three shorter
paragraphs to improve readability: first, state that AUTH_EE_* (e.g.,
AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the identityProviders
config section; second, explain that starting in v5.0.2 the env var path was
removed and Sourcebot no longer reads those vars; and optionally add a third
short sentence noting that upgrades from v5.0.0 or v5.0.1 are affected if
providers were only configured via those env vars. Keep each paragraph to 1–3
sentences and preserve the references to AUTH_EE_*, identityProviders, and
v5.0.2.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@docs/docs/upgrade/v4-to-v5-guide.mdx`:
- Line 186: The paragraph about deprecation of AUTH_EE_* env vars should be
split into two or three shorter paragraphs to improve readability: first, state
that AUTH_EE_* (e.g., AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the
identityProviders config section; second, explain that starting in v5.0.2 the
env var path was removed and Sourcebot no longer reads those vars; and
optionally add a third short sentence noting that upgrades from v5.0.0 or v5.0.1
are affected if providers were only configured via those env vars. Keep each
paragraph to 1–3 sentences and preserve the references to AUTH_EE_*,
identityProviders, and v5.0.2.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 9a29743a-acff-4895-ab84-3f55dfe2cb34

📥 Commits

Reviewing files that changed from the base of the PR and between 014d1b4 and 89dbcd5.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • docs/docs/upgrade/v4-to-v5-guide.mdx
✅ Files skipped from review due to trivial changes (1)
  • CHANGELOG.md

@brendan-kellam
brendan-kellam merged commit d2843aa into mainJun 10, 2026
9 of 10 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/remove-deprecated-sso-env-vars branch June 10, 2026 16:25
@github-actionsgithub-actionsBot mentioned this pull request Jun 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore: remove deprecated env-var identity provider configuration - #1297

Merged
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars
Jun 10, 2026
Merged

chore: remove deprecated env-var identity provider configuration#1297
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Summary

Removes support for configuring identity providers via the deprecated AUTH_EE_* environment variables for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID. These providers must now be configured through the identityProviders section of the config file, which is already a complete replacement (every one of these providers is supported there).

GCP IAP is intentionally unaffectedAUTH_EE_GCP_IAP_ENABLED and AUTH_EE_GCP_IAP_AUDIENCE remain supported (they're also read in layout.tsx / onboard/page.tsx to drive the IAP bridge sign-in). AUTH_EE_ALLOW_EMAIL_ACCOUNT_LINKING is also untouched (it's a behavioral flag, not a provider credential).

Changes

  • packages/web/src/ee/features/sso/sso.ts — removed the deprecated env-var provider blocks from the identityProviders.length == 0 path (kept GCP IAP).
  • packages/backend/src/ee/tokenRefresh.ts — removed getDeprecatedEnvCredentials and its fallback in refreshOAuthToken; token refresh now relies solely on config-file provider credentials.
  • packages/shared/src/env.server.ts — removed the deprecated AUTH_EE_{GITHUB,GITLAB,GOOGLE,OKTA,KEYCLOAK,MICROSOFT_ENTRA_ID}_* env var declarations.

Breaking change

Deployments configuring any of the six providers via AUTH_EE_* environment variables must migrate to the identityProviders config-file section. No functionality is lost — only the configuration mechanism changes.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Breaking Changes

    • Removed support for configuring GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID via deprecated AUTH_EE_* environment variables. These providers must be configured in the config file’s identityProviders section; providers still configured only via env vars will stop appearing on the login screen. GCP IAP env vars remain supported.
  • Documentation

    • Upgrade guide updated with migration steps, examples, and a GitHub config example.

Removes support for configuring GitHub, GitLab, Google, Okta, Keycloak, and
Microsoft Entra ID identity providers via the deprecated AUTH_EE_*_CLIENT_ID/
SECRET/etc. environment variables. These providers must now be defined through
the identityProviders section of the config file. GCP IAP env vars
(AUTH_EE_GCP_IAP_ENABLED / AUTH_EE_GCP_IAP_AUDIENCE) are unaffected.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a150cfa-3476-4776-a4c7-88ca95465523

📥 Commits

Reviewing files that changed from the base of the PR and between 89dbcd5 and 0cc3bb8.

📒 Files selected for processing (1)
  • CHANGELOG.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • CHANGELOG.md

Walkthrough

This PR removes deprecated AUTH_EE_* identity-provider environment variables from the server schema, removes env-var fallback from token refresh and SSO initialization, and adds a breaking-change note and upgrade guidance directing users to the config file identityProviders section.

Changes

Remove deprecated OAuth environment variable fallback

Layer / File(s)Summary
Environment schema removal
packages/shared/src/env.server.ts
The deprecated AUTH_EE_* identity provider environment variable block is removed from the server schema, eliminating all legacy OAuth provider credential definitions for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID.
Token refresh and SSO cleanup
packages/backend/src/ee/tokenRefresh.ts, packages/web/src/ee/features/sso/sso.ts
The getDeprecatedEnvCredentials helper is removed and refreshOAuthToken now logs an error and returns null instead of falling back to deprecated env vars when no provider config exists; SSO initialization no longer constructs providers from env.AUTH_EE_* variables when config providers are empty.
Changelog and upgrade guide updates
CHANGELOG.md, docs/docs/upgrade/v4-to-v5-guide.mdx
A breaking-change note documents the removal of AUTH_EE_* environment variable support and the upgrade guide adds migration steps and examples to move provider configuration into the config file identityProviders array.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#841: Directly modifies the token refresh back-compat flow by adding the deprecated AUTH_EE_* env-variable fallback that this PR removes.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: removal of deprecated environment variable-based identity provider configuration.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/remove-deprecated-sso-env-vars

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 3 commits June 9, 2026 20:49
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/ee/tokenRefresh.ts (1)

52-62: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Update docstring to remove outdated reference to deprecated env vars.

Line 57 still mentions that token refresh attempts use "client credentials from the config file (or deprecated env vars)." Since this PR removes the deprecated env-var fallback, the docstring should be updated.

📝 Proposed fix
 /**
* Ensures the OAuth access token for a given account is fresh.
*
* - If the token is not expired (or has no expiry), decrypts and returns it as-is.
* - If the token is expired or near expiry, attempts a refresh using the OAuth
- * client credentials from the config file (or deprecated env vars).+ * client credentials from the config file.
* - On successful refresh: persists the new tokens to the DB, clears any
* tokenRefreshErrorMessage, and returns the fresh access token.
* - On failure: sets tokenRefreshErrorMessage on the account and throws, so
* the calling job fails with a clear error.
*/
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/ee/tokenRefresh.ts` around lines 52 - 62, Update the top
docstring in tokenRefresh.ts to remove the outdated mention of deprecated env
vars: change the line that currently reads that refresh attempts use "client
credentials from the config file (or deprecated env vars)" to state they use
OAuth client credentials from the config file only; ensure any other bullets in
the same comment no longer reference deprecated env vars so the docstring
accurately reflects the removed fallback.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In `@packages/backend/src/ee/tokenRefresh.ts`:
- Around line 52-62: Update the top docstring in tokenRefresh.ts to remove the
outdated mention of deprecated env vars: change the line that currently reads
that refresh attempts use "client credentials from the config file (or
deprecated env vars)" to state they use OAuth client credentials from the config
file only; ensure any other bullets in the same comment no longer reference
deprecated env vars so the docstring accurately reflects the removed fallback.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 14ff19a4-9283-4e79-9b87-a8c834bd0b71

📥 Commits

Reviewing files that changed from the base of the PR and between cfab0cf and 014d1b4.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/tokenRefresh.ts
  • packages/shared/src/env.server.ts
  • packages/web/src/ee/features/sso/sso.ts
💤 Files with no reviewable changes (2)
  • packages/web/src/ee/features/sso/sso.ts
  • packages/shared/src/env.server.ts

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
docs/docs/upgrade/v4-to-v5-guide.mdx (1)

186-186: ⚡ Quick win

Break this paragraph into shorter chunks.

This paragraph contains 5 sentences. As per coding guidelines, documentation should prefer short paragraphs (1-3 sentences) to improve readability. Consider breaking this into 2-3 shorter paragraphs to align with the guideline.

♻️ Suggested restructuring
-In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file. Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen. This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.+In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file.++Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen.++This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/docs/upgrade/v4-to-v5-guide.mdx` at line 186, The paragraph about
deprecation of AUTH_EE_* env vars should be split into two or three shorter
paragraphs to improve readability: first, state that AUTH_EE_* (e.g.,
AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the identityProviders
config section; second, explain that starting in v5.0.2 the env var path was
removed and Sourcebot no longer reads those vars; and optionally add a third
short sentence noting that upgrades from v5.0.0 or v5.0.1 are affected if
providers were only configured via those env vars. Keep each paragraph to 1–3
sentences and preserve the references to AUTH_EE_*, identityProviders, and
v5.0.2.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@docs/docs/upgrade/v4-to-v5-guide.mdx`:
- Line 186: The paragraph about deprecation of AUTH_EE_* env vars should be
split into two or three shorter paragraphs to improve readability: first, state
that AUTH_EE_* (e.g., AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the
identityProviders config section; second, explain that starting in v5.0.2 the
env var path was removed and Sourcebot no longer reads those vars; and
optionally add a third short sentence noting that upgrades from v5.0.0 or v5.0.1
are affected if providers were only configured via those env vars. Keep each
paragraph to 1–3 sentences and preserve the references to AUTH_EE_*,
identityProviders, and v5.0.2.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 9a29743a-acff-4895-ab84-3f55dfe2cb34

📥 Commits

Reviewing files that changed from the base of the PR and between 014d1b4 and 89dbcd5.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • docs/docs/upgrade/v4-to-v5-guide.mdx
✅ Files skipped from review due to trivial changes (1)
  • CHANGELOG.md

@brendan-kellam
brendan-kellam merged commit d2843aa into mainJun 10, 2026
9 of 10 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/remove-deprecated-sso-env-vars branch June 10, 2026 16:25
@github-actionsgithub-actionsBot mentioned this pull request Jun 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: remove deprecated env-var identity provider configuration - #1297

Merged
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars
Jun 10, 2026
Merged

chore: remove deprecated env-var identity provider configuration#1297
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Summary

Removes support for configuring identity providers via the deprecated AUTH_EE_* environment variables for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID. These providers must now be configured through the identityProviders section of the config file, which is already a complete replacement (every one of these providers is supported there).

GCP IAP is intentionally unaffectedAUTH_EE_GCP_IAP_ENABLED and AUTH_EE_GCP_IAP_AUDIENCE remain supported (they're also read in layout.tsx / onboard/page.tsx to drive the IAP bridge sign-in). AUTH_EE_ALLOW_EMAIL_ACCOUNT_LINKING is also untouched (it's a behavioral flag, not a provider credential).

Changes

  • packages/web/src/ee/features/sso/sso.ts — removed the deprecated env-var provider blocks from the identityProviders.length == 0 path (kept GCP IAP).
  • packages/backend/src/ee/tokenRefresh.ts — removed getDeprecatedEnvCredentials and its fallback in refreshOAuthToken; token refresh now relies solely on config-file provider credentials.
  • packages/shared/src/env.server.ts — removed the deprecated AUTH_EE_{GITHUB,GITLAB,GOOGLE,OKTA,KEYCLOAK,MICROSOFT_ENTRA_ID}_* env var declarations.

Breaking change

Deployments configuring any of the six providers via AUTH_EE_* environment variables must migrate to the identityProviders config-file section. No functionality is lost — only the configuration mechanism changes.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Breaking Changes

    • Removed support for configuring GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID via deprecated AUTH_EE_* environment variables. These providers must be configured in the config file’s identityProviders section; providers still configured only via env vars will stop appearing on the login screen. GCP IAP env vars remain supported.
  • Documentation

    • Upgrade guide updated with migration steps, examples, and a GitHub config example.

Removes support for configuring GitHub, GitLab, Google, Okta, Keycloak, and
Microsoft Entra ID identity providers via the deprecated AUTH_EE_*_CLIENT_ID/
SECRET/etc. environment variables. These providers must now be defined through
the identityProviders section of the config file. GCP IAP env vars
(AUTH_EE_GCP_IAP_ENABLED / AUTH_EE_GCP_IAP_AUDIENCE) are unaffected.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a150cfa-3476-4776-a4c7-88ca95465523

📥 Commits

Reviewing files that changed from the base of the PR and between 89dbcd5 and 0cc3bb8.

📒 Files selected for processing (1)
  • CHANGELOG.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • CHANGELOG.md

Walkthrough

This PR removes deprecated AUTH_EE_* identity-provider environment variables from the server schema, removes env-var fallback from token refresh and SSO initialization, and adds a breaking-change note and upgrade guidance directing users to the config file identityProviders section.

Changes

Remove deprecated OAuth environment variable fallback

Layer / File(s)Summary
Environment schema removal
packages/shared/src/env.server.ts
The deprecated AUTH_EE_* identity provider environment variable block is removed from the server schema, eliminating all legacy OAuth provider credential definitions for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID.
Token refresh and SSO cleanup
packages/backend/src/ee/tokenRefresh.ts, packages/web/src/ee/features/sso/sso.ts
The getDeprecatedEnvCredentials helper is removed and refreshOAuthToken now logs an error and returns null instead of falling back to deprecated env vars when no provider config exists; SSO initialization no longer constructs providers from env.AUTH_EE_* variables when config providers are empty.
Changelog and upgrade guide updates
CHANGELOG.md, docs/docs/upgrade/v4-to-v5-guide.mdx
A breaking-change note documents the removal of AUTH_EE_* environment variable support and the upgrade guide adds migration steps and examples to move provider configuration into the config file identityProviders array.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#841: Directly modifies the token refresh back-compat flow by adding the deprecated AUTH_EE_* env-variable fallback that this PR removes.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: removal of deprecated environment variable-based identity provider configuration.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/remove-deprecated-sso-env-vars

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 3 commits June 9, 2026 20:49
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/ee/tokenRefresh.ts (1)

52-62: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Update docstring to remove outdated reference to deprecated env vars.

Line 57 still mentions that token refresh attempts use "client credentials from the config file (or deprecated env vars)." Since this PR removes the deprecated env-var fallback, the docstring should be updated.

📝 Proposed fix
 /**
* Ensures the OAuth access token for a given account is fresh.
*
* - If the token is not expired (or has no expiry), decrypts and returns it as-is.
* - If the token is expired or near expiry, attempts a refresh using the OAuth
- * client credentials from the config file (or deprecated env vars).+ * client credentials from the config file.
* - On successful refresh: persists the new tokens to the DB, clears any
* tokenRefreshErrorMessage, and returns the fresh access token.
* - On failure: sets tokenRefreshErrorMessage on the account and throws, so
* the calling job fails with a clear error.
*/
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/ee/tokenRefresh.ts` around lines 52 - 62, Update the top
docstring in tokenRefresh.ts to remove the outdated mention of deprecated env
vars: change the line that currently reads that refresh attempts use "client
credentials from the config file (or deprecated env vars)" to state they use
OAuth client credentials from the config file only; ensure any other bullets in
the same comment no longer reference deprecated env vars so the docstring
accurately reflects the removed fallback.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In `@packages/backend/src/ee/tokenRefresh.ts`:
- Around line 52-62: Update the top docstring in tokenRefresh.ts to remove the
outdated mention of deprecated env vars: change the line that currently reads
that refresh attempts use "client credentials from the config file (or
deprecated env vars)" to state they use OAuth client credentials from the config
file only; ensure any other bullets in the same comment no longer reference
deprecated env vars so the docstring accurately reflects the removed fallback.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 14ff19a4-9283-4e79-9b87-a8c834bd0b71

📥 Commits

Reviewing files that changed from the base of the PR and between cfab0cf and 014d1b4.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/tokenRefresh.ts
  • packages/shared/src/env.server.ts
  • packages/web/src/ee/features/sso/sso.ts
💤 Files with no reviewable changes (2)
  • packages/web/src/ee/features/sso/sso.ts
  • packages/shared/src/env.server.ts

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
docs/docs/upgrade/v4-to-v5-guide.mdx (1)

186-186: ⚡ Quick win

Break this paragraph into shorter chunks.

This paragraph contains 5 sentences. As per coding guidelines, documentation should prefer short paragraphs (1-3 sentences) to improve readability. Consider breaking this into 2-3 shorter paragraphs to align with the guideline.

♻️ Suggested restructuring
-In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file. Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen. This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.+In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file.++Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen.++This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/docs/upgrade/v4-to-v5-guide.mdx` at line 186, The paragraph about
deprecation of AUTH_EE_* env vars should be split into two or three shorter
paragraphs to improve readability: first, state that AUTH_EE_* (e.g.,
AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the identityProviders
config section; second, explain that starting in v5.0.2 the env var path was
removed and Sourcebot no longer reads those vars; and optionally add a third
short sentence noting that upgrades from v5.0.0 or v5.0.1 are affected if
providers were only configured via those env vars. Keep each paragraph to 1–3
sentences and preserve the references to AUTH_EE_*, identityProviders, and
v5.0.2.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@docs/docs/upgrade/v4-to-v5-guide.mdx`:
- Line 186: The paragraph about deprecation of AUTH_EE_* env vars should be
split into two or three shorter paragraphs to improve readability: first, state
that AUTH_EE_* (e.g., AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the
identityProviders config section; second, explain that starting in v5.0.2 the
env var path was removed and Sourcebot no longer reads those vars; and
optionally add a third short sentence noting that upgrades from v5.0.0 or v5.0.1
are affected if providers were only configured via those env vars. Keep each
paragraph to 1–3 sentences and preserve the references to AUTH_EE_*,
identityProviders, and v5.0.2.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 9a29743a-acff-4895-ab84-3f55dfe2cb34

📥 Commits

Reviewing files that changed from the base of the PR and between 014d1b4 and 89dbcd5.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • docs/docs/upgrade/v4-to-v5-guide.mdx
✅ Files skipped from review due to trivial changes (1)
  • CHANGELOG.md

@brendan-kellam
brendan-kellam merged commit d2843aa into mainJun 10, 2026
9 of 10 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/remove-deprecated-sso-env-vars branch June 10, 2026 16:25
@github-actionsgithub-actionsBot mentioned this pull request Jun 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: remove deprecated env-var identity provider configuration - #1297

Merged
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars
Jun 10, 2026
Merged

chore: remove deprecated env-var identity provider configuration#1297
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Summary

Removes support for configuring identity providers via the deprecated AUTH_EE_* environment variables for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID. These providers must now be configured through the identityProviders section of the config file, which is already a complete replacement (every one of these providers is supported there).

GCP IAP is intentionally unaffectedAUTH_EE_GCP_IAP_ENABLED and AUTH_EE_GCP_IAP_AUDIENCE remain supported (they're also read in layout.tsx / onboard/page.tsx to drive the IAP bridge sign-in). AUTH_EE_ALLOW_EMAIL_ACCOUNT_LINKING is also untouched (it's a behavioral flag, not a provider credential).

Changes

  • packages/web/src/ee/features/sso/sso.ts — removed the deprecated env-var provider blocks from the identityProviders.length == 0 path (kept GCP IAP).
  • packages/backend/src/ee/tokenRefresh.ts — removed getDeprecatedEnvCredentials and its fallback in refreshOAuthToken; token refresh now relies solely on config-file provider credentials.
  • packages/shared/src/env.server.ts — removed the deprecated AUTH_EE_{GITHUB,GITLAB,GOOGLE,OKTA,KEYCLOAK,MICROSOFT_ENTRA_ID}_* env var declarations.

Breaking change

Deployments configuring any of the six providers via AUTH_EE_* environment variables must migrate to the identityProviders config-file section. No functionality is lost — only the configuration mechanism changes.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Breaking Changes

    • Removed support for configuring GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID via deprecated AUTH_EE_* environment variables. These providers must be configured in the config file’s identityProviders section; providers still configured only via env vars will stop appearing on the login screen. GCP IAP env vars remain supported.
  • Documentation

    • Upgrade guide updated with migration steps, examples, and a GitHub config example.

Removes support for configuring GitHub, GitLab, Google, Okta, Keycloak, and
Microsoft Entra ID identity providers via the deprecated AUTH_EE_*_CLIENT_ID/
SECRET/etc. environment variables. These providers must now be defined through
the identityProviders section of the config file. GCP IAP env vars
(AUTH_EE_GCP_IAP_ENABLED / AUTH_EE_GCP_IAP_AUDIENCE) are unaffected.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a150cfa-3476-4776-a4c7-88ca95465523

📥 Commits

Reviewing files that changed from the base of the PR and between 89dbcd5 and 0cc3bb8.

📒 Files selected for processing (1)
  • CHANGELOG.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • CHANGELOG.md

Walkthrough

This PR removes deprecated AUTH_EE_* identity-provider environment variables from the server schema, removes env-var fallback from token refresh and SSO initialization, and adds a breaking-change note and upgrade guidance directing users to the config file identityProviders section.

Changes

Remove deprecated OAuth environment variable fallback

Layer / File(s)Summary
Environment schema removal
packages/shared/src/env.server.ts
The deprecated AUTH_EE_* identity provider environment variable block is removed from the server schema, eliminating all legacy OAuth provider credential definitions for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID.
Token refresh and SSO cleanup
packages/backend/src/ee/tokenRefresh.ts, packages/web/src/ee/features/sso/sso.ts
The getDeprecatedEnvCredentials helper is removed and refreshOAuthToken now logs an error and returns null instead of falling back to deprecated env vars when no provider config exists; SSO initialization no longer constructs providers from env.AUTH_EE_* variables when config providers are empty.
Changelog and upgrade guide updates
CHANGELOG.md, docs/docs/upgrade/v4-to-v5-guide.mdx
A breaking-change note documents the removal of AUTH_EE_* environment variable support and the upgrade guide adds migration steps and examples to move provider configuration into the config file identityProviders array.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#841: Directly modifies the token refresh back-compat flow by adding the deprecated AUTH_EE_* env-variable fallback that this PR removes.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: removal of deprecated environment variable-based identity provider configuration.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/remove-deprecated-sso-env-vars

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 3 commits June 9, 2026 20:49
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/ee/tokenRefresh.ts (1)

52-62: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Update docstring to remove outdated reference to deprecated env vars.

Line 57 still mentions that token refresh attempts use "client credentials from the config file (or deprecated env vars)." Since this PR removes the deprecated env-var fallback, the docstring should be updated.

📝 Proposed fix
 /**
* Ensures the OAuth access token for a given account is fresh.
*
* - If the token is not expired (or has no expiry), decrypts and returns it as-is.
* - If the token is expired or near expiry, attempts a refresh using the OAuth
- * client credentials from the config file (or deprecated env vars).+ * client credentials from the config file.
* - On successful refresh: persists the new tokens to the DB, clears any
* tokenRefreshErrorMessage, and returns the fresh access token.
* - On failure: sets tokenRefreshErrorMessage on the account and throws, so
* the calling job fails with a clear error.
*/
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/ee/tokenRefresh.ts` around lines 52 - 62, Update the top
docstring in tokenRefresh.ts to remove the outdated mention of deprecated env
vars: change the line that currently reads that refresh attempts use "client
credentials from the config file (or deprecated env vars)" to state they use
OAuth client credentials from the config file only; ensure any other bullets in
the same comment no longer reference deprecated env vars so the docstring
accurately reflects the removed fallback.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In `@packages/backend/src/ee/tokenRefresh.ts`:
- Around line 52-62: Update the top docstring in tokenRefresh.ts to remove the
outdated mention of deprecated env vars: change the line that currently reads
that refresh attempts use "client credentials from the config file (or
deprecated env vars)" to state they use OAuth client credentials from the config
file only; ensure any other bullets in the same comment no longer reference
deprecated env vars so the docstring accurately reflects the removed fallback.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 14ff19a4-9283-4e79-9b87-a8c834bd0b71

📥 Commits

Reviewing files that changed from the base of the PR and between cfab0cf and 014d1b4.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/tokenRefresh.ts
  • packages/shared/src/env.server.ts
  • packages/web/src/ee/features/sso/sso.ts
💤 Files with no reviewable changes (2)
  • packages/web/src/ee/features/sso/sso.ts
  • packages/shared/src/env.server.ts

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
docs/docs/upgrade/v4-to-v5-guide.mdx (1)

186-186: ⚡ Quick win

Break this paragraph into shorter chunks.

This paragraph contains 5 sentences. As per coding guidelines, documentation should prefer short paragraphs (1-3 sentences) to improve readability. Consider breaking this into 2-3 shorter paragraphs to align with the guideline.

♻️ Suggested restructuring
-In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file. Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen. This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.+In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file.++Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen.++This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/docs/upgrade/v4-to-v5-guide.mdx` at line 186, The paragraph about
deprecation of AUTH_EE_* env vars should be split into two or three shorter
paragraphs to improve readability: first, state that AUTH_EE_* (e.g.,
AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the identityProviders
config section; second, explain that starting in v5.0.2 the env var path was
removed and Sourcebot no longer reads those vars; and optionally add a third
short sentence noting that upgrades from v5.0.0 or v5.0.1 are affected if
providers were only configured via those env vars. Keep each paragraph to 1–3
sentences and preserve the references to AUTH_EE_*, identityProviders, and
v5.0.2.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@docs/docs/upgrade/v4-to-v5-guide.mdx`:
- Line 186: The paragraph about deprecation of AUTH_EE_* env vars should be
split into two or three shorter paragraphs to improve readability: first, state
that AUTH_EE_* (e.g., AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the
identityProviders config section; second, explain that starting in v5.0.2 the
env var path was removed and Sourcebot no longer reads those vars; and
optionally add a third short sentence noting that upgrades from v5.0.0 or v5.0.1
are affected if providers were only configured via those env vars. Keep each
paragraph to 1–3 sentences and preserve the references to AUTH_EE_*,
identityProviders, and v5.0.2.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 9a29743a-acff-4895-ab84-3f55dfe2cb34

📥 Commits

Reviewing files that changed from the base of the PR and between 014d1b4 and 89dbcd5.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • docs/docs/upgrade/v4-to-v5-guide.mdx
✅ Files skipped from review due to trivial changes (1)
  • CHANGELOG.md

@brendan-kellam
brendan-kellam merged commit d2843aa into mainJun 10, 2026
9 of 10 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/remove-deprecated-sso-env-vars branch June 10, 2026 16:25
@github-actionsgithub-actionsBot mentioned this pull request Jun 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore: remove deprecated env-var identity provider configuration - #1297

Merged
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars
Jun 10, 2026
Merged

chore: remove deprecated env-var identity provider configuration#1297
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Summary

Removes support for configuring identity providers via the deprecated AUTH_EE_* environment variables for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID. These providers must now be configured through the identityProviders section of the config file, which is already a complete replacement (every one of these providers is supported there).

GCP IAP is intentionally unaffectedAUTH_EE_GCP_IAP_ENABLED and AUTH_EE_GCP_IAP_AUDIENCE remain supported (they're also read in layout.tsx / onboard/page.tsx to drive the IAP bridge sign-in). AUTH_EE_ALLOW_EMAIL_ACCOUNT_LINKING is also untouched (it's a behavioral flag, not a provider credential).

Changes

  • packages/web/src/ee/features/sso/sso.ts — removed the deprecated env-var provider blocks from the identityProviders.length == 0 path (kept GCP IAP).
  • packages/backend/src/ee/tokenRefresh.ts — removed getDeprecatedEnvCredentials and its fallback in refreshOAuthToken; token refresh now relies solely on config-file provider credentials.
  • packages/shared/src/env.server.ts — removed the deprecated AUTH_EE_{GITHUB,GITLAB,GOOGLE,OKTA,KEYCLOAK,MICROSOFT_ENTRA_ID}_* env var declarations.

Breaking change

Deployments configuring any of the six providers via AUTH_EE_* environment variables must migrate to the identityProviders config-file section. No functionality is lost — only the configuration mechanism changes.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Breaking Changes

    • Removed support for configuring GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID via deprecated AUTH_EE_* environment variables. These providers must be configured in the config file’s identityProviders section; providers still configured only via env vars will stop appearing on the login screen. GCP IAP env vars remain supported.
  • Documentation

    • Upgrade guide updated with migration steps, examples, and a GitHub config example.

Removes support for configuring GitHub, GitLab, Google, Okta, Keycloak, and
Microsoft Entra ID identity providers via the deprecated AUTH_EE_*_CLIENT_ID/
SECRET/etc. environment variables. These providers must now be defined through
the identityProviders section of the config file. GCP IAP env vars
(AUTH_EE_GCP_IAP_ENABLED / AUTH_EE_GCP_IAP_AUDIENCE) are unaffected.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a150cfa-3476-4776-a4c7-88ca95465523

📥 Commits

Reviewing files that changed from the base of the PR and between 89dbcd5 and 0cc3bb8.

📒 Files selected for processing (1)
  • CHANGELOG.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • CHANGELOG.md

Walkthrough

This PR removes deprecated AUTH_EE_* identity-provider environment variables from the server schema, removes env-var fallback from token refresh and SSO initialization, and adds a breaking-change note and upgrade guidance directing users to the config file identityProviders section.

Changes

Remove deprecated OAuth environment variable fallback

Layer / File(s)Summary
Environment schema removal
packages/shared/src/env.server.ts
The deprecated AUTH_EE_* identity provider environment variable block is removed from the server schema, eliminating all legacy OAuth provider credential definitions for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID.
Token refresh and SSO cleanup
packages/backend/src/ee/tokenRefresh.ts, packages/web/src/ee/features/sso/sso.ts
The getDeprecatedEnvCredentials helper is removed and refreshOAuthToken now logs an error and returns null instead of falling back to deprecated env vars when no provider config exists; SSO initialization no longer constructs providers from env.AUTH_EE_* variables when config providers are empty.
Changelog and upgrade guide updates
CHANGELOG.md, docs/docs/upgrade/v4-to-v5-guide.mdx
A breaking-change note documents the removal of AUTH_EE_* environment variable support and the upgrade guide adds migration steps and examples to move provider configuration into the config file identityProviders array.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#841: Directly modifies the token refresh back-compat flow by adding the deprecated AUTH_EE_* env-variable fallback that this PR removes.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: removal of deprecated environment variable-based identity provider configuration.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/remove-deprecated-sso-env-vars

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 3 commits June 9, 2026 20:49
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/ee/tokenRefresh.ts (1)

52-62: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Update docstring to remove outdated reference to deprecated env vars.

Line 57 still mentions that token refresh attempts use "client credentials from the config file (or deprecated env vars)." Since this PR removes the deprecated env-var fallback, the docstring should be updated.

📝 Proposed fix
 /**
* Ensures the OAuth access token for a given account is fresh.
*
* - If the token is not expired (or has no expiry), decrypts and returns it as-is.
* - If the token is expired or near expiry, attempts a refresh using the OAuth
- * client credentials from the config file (or deprecated env vars).+ * client credentials from the config file.
* - On successful refresh: persists the new tokens to the DB, clears any
* tokenRefreshErrorMessage, and returns the fresh access token.
* - On failure: sets tokenRefreshErrorMessage on the account and throws, so
* the calling job fails with a clear error.
*/
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/ee/tokenRefresh.ts` around lines 52 - 62, Update the top
docstring in tokenRefresh.ts to remove the outdated mention of deprecated env
vars: change the line that currently reads that refresh attempts use "client
credentials from the config file (or deprecated env vars)" to state they use
OAuth client credentials from the config file only; ensure any other bullets in
the same comment no longer reference deprecated env vars so the docstring
accurately reflects the removed fallback.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In `@packages/backend/src/ee/tokenRefresh.ts`:
- Around line 52-62: Update the top docstring in tokenRefresh.ts to remove the
outdated mention of deprecated env vars: change the line that currently reads
that refresh attempts use "client credentials from the config file (or
deprecated env vars)" to state they use OAuth client credentials from the config
file only; ensure any other bullets in the same comment no longer reference
deprecated env vars so the docstring accurately reflects the removed fallback.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 14ff19a4-9283-4e79-9b87-a8c834bd0b71

📥 Commits

Reviewing files that changed from the base of the PR and between cfab0cf and 014d1b4.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/tokenRefresh.ts
  • packages/shared/src/env.server.ts
  • packages/web/src/ee/features/sso/sso.ts
💤 Files with no reviewable changes (2)
  • packages/web/src/ee/features/sso/sso.ts
  • packages/shared/src/env.server.ts

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
docs/docs/upgrade/v4-to-v5-guide.mdx (1)

186-186: ⚡ Quick win

Break this paragraph into shorter chunks.

This paragraph contains 5 sentences. As per coding guidelines, documentation should prefer short paragraphs (1-3 sentences) to improve readability. Consider breaking this into 2-3 shorter paragraphs to align with the guideline.

♻️ Suggested restructuring
-In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file. Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen. This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.+In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file.++Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen.++This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/docs/upgrade/v4-to-v5-guide.mdx` at line 186, The paragraph about
deprecation of AUTH_EE_* env vars should be split into two or three shorter
paragraphs to improve readability: first, state that AUTH_EE_* (e.g.,
AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the identityProviders
config section; second, explain that starting in v5.0.2 the env var path was
removed and Sourcebot no longer reads those vars; and optionally add a third
short sentence noting that upgrades from v5.0.0 or v5.0.1 are affected if
providers were only configured via those env vars. Keep each paragraph to 1–3
sentences and preserve the references to AUTH_EE_*, identityProviders, and
v5.0.2.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@docs/docs/upgrade/v4-to-v5-guide.mdx`:
- Line 186: The paragraph about deprecation of AUTH_EE_* env vars should be
split into two or three shorter paragraphs to improve readability: first, state
that AUTH_EE_* (e.g., AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the
identityProviders config section; second, explain that starting in v5.0.2 the
env var path was removed and Sourcebot no longer reads those vars; and
optionally add a third short sentence noting that upgrades from v5.0.0 or v5.0.1
are affected if providers were only configured via those env vars. Keep each
paragraph to 1–3 sentences and preserve the references to AUTH_EE_*,
identityProviders, and v5.0.2.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 9a29743a-acff-4895-ab84-3f55dfe2cb34

📥 Commits

Reviewing files that changed from the base of the PR and between 014d1b4 and 89dbcd5.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • docs/docs/upgrade/v4-to-v5-guide.mdx
✅ Files skipped from review due to trivial changes (1)
  • CHANGELOG.md

@brendan-kellam
brendan-kellam merged commit d2843aa into mainJun 10, 2026
9 of 10 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/remove-deprecated-sso-env-vars branch June 10, 2026 16:25
@github-actionsgithub-actionsBot mentioned this pull request Jun 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: remove deprecated env-var identity provider configuration - #1297

Merged
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars
Jun 10, 2026
Merged

chore: remove deprecated env-var identity provider configuration#1297
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Summary

Removes support for configuring identity providers via the deprecated AUTH_EE_* environment variables for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID. These providers must now be configured through the identityProviders section of the config file, which is already a complete replacement (every one of these providers is supported there).

GCP IAP is intentionally unaffectedAUTH_EE_GCP_IAP_ENABLED and AUTH_EE_GCP_IAP_AUDIENCE remain supported (they're also read in layout.tsx / onboard/page.tsx to drive the IAP bridge sign-in). AUTH_EE_ALLOW_EMAIL_ACCOUNT_LINKING is also untouched (it's a behavioral flag, not a provider credential).

Changes

  • packages/web/src/ee/features/sso/sso.ts — removed the deprecated env-var provider blocks from the identityProviders.length == 0 path (kept GCP IAP).
  • packages/backend/src/ee/tokenRefresh.ts — removed getDeprecatedEnvCredentials and its fallback in refreshOAuthToken; token refresh now relies solely on config-file provider credentials.
  • packages/shared/src/env.server.ts — removed the deprecated AUTH_EE_{GITHUB,GITLAB,GOOGLE,OKTA,KEYCLOAK,MICROSOFT_ENTRA_ID}_* env var declarations.

Breaking change

Deployments configuring any of the six providers via AUTH_EE_* environment variables must migrate to the identityProviders config-file section. No functionality is lost — only the configuration mechanism changes.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Breaking Changes

    • Removed support for configuring GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID via deprecated AUTH_EE_* environment variables. These providers must be configured in the config file’s identityProviders section; providers still configured only via env vars will stop appearing on the login screen. GCP IAP env vars remain supported.
  • Documentation

    • Upgrade guide updated with migration steps, examples, and a GitHub config example.

Removes support for configuring GitHub, GitLab, Google, Okta, Keycloak, and
Microsoft Entra ID identity providers via the deprecated AUTH_EE_*_CLIENT_ID/
SECRET/etc. environment variables. These providers must now be defined through
the identityProviders section of the config file. GCP IAP env vars
(AUTH_EE_GCP_IAP_ENABLED / AUTH_EE_GCP_IAP_AUDIENCE) are unaffected.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a150cfa-3476-4776-a4c7-88ca95465523

📥 Commits

Reviewing files that changed from the base of the PR and between 89dbcd5 and 0cc3bb8.

📒 Files selected for processing (1)
  • CHANGELOG.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • CHANGELOG.md

Walkthrough

This PR removes deprecated AUTH_EE_* identity-provider environment variables from the server schema, removes env-var fallback from token refresh and SSO initialization, and adds a breaking-change note and upgrade guidance directing users to the config file identityProviders section.

Changes

Remove deprecated OAuth environment variable fallback

Layer / File(s)Summary
Environment schema removal
packages/shared/src/env.server.ts
The deprecated AUTH_EE_* identity provider environment variable block is removed from the server schema, eliminating all legacy OAuth provider credential definitions for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID.
Token refresh and SSO cleanup
packages/backend/src/ee/tokenRefresh.ts, packages/web/src/ee/features/sso/sso.ts
The getDeprecatedEnvCredentials helper is removed and refreshOAuthToken now logs an error and returns null instead of falling back to deprecated env vars when no provider config exists; SSO initialization no longer constructs providers from env.AUTH_EE_* variables when config providers are empty.
Changelog and upgrade guide updates
CHANGELOG.md, docs/docs/upgrade/v4-to-v5-guide.mdx
A breaking-change note documents the removal of AUTH_EE_* environment variable support and the upgrade guide adds migration steps and examples to move provider configuration into the config file identityProviders array.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#841: Directly modifies the token refresh back-compat flow by adding the deprecated AUTH_EE_* env-variable fallback that this PR removes.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: removal of deprecated environment variable-based identity provider configuration.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/remove-deprecated-sso-env-vars

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 3 commits June 9, 2026 20:49
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/ee/tokenRefresh.ts (1)

52-62: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Update docstring to remove outdated reference to deprecated env vars.

Line 57 still mentions that token refresh attempts use "client credentials from the config file (or deprecated env vars)." Since this PR removes the deprecated env-var fallback, the docstring should be updated.

📝 Proposed fix
 /**
* Ensures the OAuth access token for a given account is fresh.
*
* - If the token is not expired (or has no expiry), decrypts and returns it as-is.
* - If the token is expired or near expiry, attempts a refresh using the OAuth
- * client credentials from the config file (or deprecated env vars).+ * client credentials from the config file.
* - On successful refresh: persists the new tokens to the DB, clears any
* tokenRefreshErrorMessage, and returns the fresh access token.
* - On failure: sets tokenRefreshErrorMessage on the account and throws, so
* the calling job fails with a clear error.
*/
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/ee/tokenRefresh.ts` around lines 52 - 62, Update the top
docstring in tokenRefresh.ts to remove the outdated mention of deprecated env
vars: change the line that currently reads that refresh attempts use "client
credentials from the config file (or deprecated env vars)" to state they use
OAuth client credentials from the config file only; ensure any other bullets in
the same comment no longer reference deprecated env vars so the docstring
accurately reflects the removed fallback.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In `@packages/backend/src/ee/tokenRefresh.ts`:
- Around line 52-62: Update the top docstring in tokenRefresh.ts to remove the
outdated mention of deprecated env vars: change the line that currently reads
that refresh attempts use "client credentials from the config file (or
deprecated env vars)" to state they use OAuth client credentials from the config
file only; ensure any other bullets in the same comment no longer reference
deprecated env vars so the docstring accurately reflects the removed fallback.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 14ff19a4-9283-4e79-9b87-a8c834bd0b71

📥 Commits

Reviewing files that changed from the base of the PR and between cfab0cf and 014d1b4.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/tokenRefresh.ts
  • packages/shared/src/env.server.ts
  • packages/web/src/ee/features/sso/sso.ts
💤 Files with no reviewable changes (2)
  • packages/web/src/ee/features/sso/sso.ts
  • packages/shared/src/env.server.ts

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
docs/docs/upgrade/v4-to-v5-guide.mdx (1)

186-186: ⚡ Quick win

Break this paragraph into shorter chunks.

This paragraph contains 5 sentences. As per coding guidelines, documentation should prefer short paragraphs (1-3 sentences) to improve readability. Consider breaking this into 2-3 shorter paragraphs to align with the guideline.

♻️ Suggested restructuring
-In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file. Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen. This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.+In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file.++Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen.++This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/docs/upgrade/v4-to-v5-guide.mdx` at line 186, The paragraph about
deprecation of AUTH_EE_* env vars should be split into two or three shorter
paragraphs to improve readability: first, state that AUTH_EE_* (e.g.,
AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the identityProviders
config section; second, explain that starting in v5.0.2 the env var path was
removed and Sourcebot no longer reads those vars; and optionally add a third
short sentence noting that upgrades from v5.0.0 or v5.0.1 are affected if
providers were only configured via those env vars. Keep each paragraph to 1–3
sentences and preserve the references to AUTH_EE_*, identityProviders, and
v5.0.2.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@docs/docs/upgrade/v4-to-v5-guide.mdx`:
- Line 186: The paragraph about deprecation of AUTH_EE_* env vars should be
split into two or three shorter paragraphs to improve readability: first, state
that AUTH_EE_* (e.g., AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the
identityProviders config section; second, explain that starting in v5.0.2 the
env var path was removed and Sourcebot no longer reads those vars; and
optionally add a third short sentence noting that upgrades from v5.0.0 or v5.0.1
are affected if providers were only configured via those env vars. Keep each
paragraph to 1–3 sentences and preserve the references to AUTH_EE_*,
identityProviders, and v5.0.2.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 9a29743a-acff-4895-ab84-3f55dfe2cb34

📥 Commits

Reviewing files that changed from the base of the PR and between 014d1b4 and 89dbcd5.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • docs/docs/upgrade/v4-to-v5-guide.mdx
✅ Files skipped from review due to trivial changes (1)
  • CHANGELOG.md

@brendan-kellam
brendan-kellam merged commit d2843aa into mainJun 10, 2026
9 of 10 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/remove-deprecated-sso-env-vars branch June 10, 2026 16:25
@github-actionsgithub-actionsBot mentioned this pull request Jun 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: remove deprecated env-var identity provider configuration - #1297

Merged
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars
Jun 10, 2026
Merged

chore: remove deprecated env-var identity provider configuration#1297
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Summary

Removes support for configuring identity providers via the deprecated AUTH_EE_* environment variables for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID. These providers must now be configured through the identityProviders section of the config file, which is already a complete replacement (every one of these providers is supported there).

GCP IAP is intentionally unaffectedAUTH_EE_GCP_IAP_ENABLED and AUTH_EE_GCP_IAP_AUDIENCE remain supported (they're also read in layout.tsx / onboard/page.tsx to drive the IAP bridge sign-in). AUTH_EE_ALLOW_EMAIL_ACCOUNT_LINKING is also untouched (it's a behavioral flag, not a provider credential).

Changes

  • packages/web/src/ee/features/sso/sso.ts — removed the deprecated env-var provider blocks from the identityProviders.length == 0 path (kept GCP IAP).
  • packages/backend/src/ee/tokenRefresh.ts — removed getDeprecatedEnvCredentials and its fallback in refreshOAuthToken; token refresh now relies solely on config-file provider credentials.
  • packages/shared/src/env.server.ts — removed the deprecated AUTH_EE_{GITHUB,GITLAB,GOOGLE,OKTA,KEYCLOAK,MICROSOFT_ENTRA_ID}_* env var declarations.

Breaking change

Deployments configuring any of the six providers via AUTH_EE_* environment variables must migrate to the identityProviders config-file section. No functionality is lost — only the configuration mechanism changes.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Breaking Changes

    • Removed support for configuring GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID via deprecated AUTH_EE_* environment variables. These providers must be configured in the config file’s identityProviders section; providers still configured only via env vars will stop appearing on the login screen. GCP IAP env vars remain supported.
  • Documentation

    • Upgrade guide updated with migration steps, examples, and a GitHub config example.

Removes support for configuring GitHub, GitLab, Google, Okta, Keycloak, and
Microsoft Entra ID identity providers via the deprecated AUTH_EE_*_CLIENT_ID/
SECRET/etc. environment variables. These providers must now be defined through
the identityProviders section of the config file. GCP IAP env vars
(AUTH_EE_GCP_IAP_ENABLED / AUTH_EE_GCP_IAP_AUDIENCE) are unaffected.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a150cfa-3476-4776-a4c7-88ca95465523

📥 Commits

Reviewing files that changed from the base of the PR and between 89dbcd5 and 0cc3bb8.

📒 Files selected for processing (1)
  • CHANGELOG.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • CHANGELOG.md

Walkthrough

This PR removes deprecated AUTH_EE_* identity-provider environment variables from the server schema, removes env-var fallback from token refresh and SSO initialization, and adds a breaking-change note and upgrade guidance directing users to the config file identityProviders section.

Changes

Remove deprecated OAuth environment variable fallback

Layer / File(s)Summary
Environment schema removal
packages/shared/src/env.server.ts
The deprecated AUTH_EE_* identity provider environment variable block is removed from the server schema, eliminating all legacy OAuth provider credential definitions for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID.
Token refresh and SSO cleanup
packages/backend/src/ee/tokenRefresh.ts, packages/web/src/ee/features/sso/sso.ts
The getDeprecatedEnvCredentials helper is removed and refreshOAuthToken now logs an error and returns null instead of falling back to deprecated env vars when no provider config exists; SSO initialization no longer constructs providers from env.AUTH_EE_* variables when config providers are empty.
Changelog and upgrade guide updates
CHANGELOG.md, docs/docs/upgrade/v4-to-v5-guide.mdx
A breaking-change note documents the removal of AUTH_EE_* environment variable support and the upgrade guide adds migration steps and examples to move provider configuration into the config file identityProviders array.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#841: Directly modifies the token refresh back-compat flow by adding the deprecated AUTH_EE_* env-variable fallback that this PR removes.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: removal of deprecated environment variable-based identity provider configuration.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/remove-deprecated-sso-env-vars

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 3 commits June 9, 2026 20:49
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/ee/tokenRefresh.ts (1)

52-62: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Update docstring to remove outdated reference to deprecated env vars.

Line 57 still mentions that token refresh attempts use "client credentials from the config file (or deprecated env vars)." Since this PR removes the deprecated env-var fallback, the docstring should be updated.

📝 Proposed fix
 /**
* Ensures the OAuth access token for a given account is fresh.
*
* - If the token is not expired (or has no expiry), decrypts and returns it as-is.
* - If the token is expired or near expiry, attempts a refresh using the OAuth
- * client credentials from the config file (or deprecated env vars).+ * client credentials from the config file.
* - On successful refresh: persists the new tokens to the DB, clears any
* tokenRefreshErrorMessage, and returns the fresh access token.
* - On failure: sets tokenRefreshErrorMessage on the account and throws, so
* the calling job fails with a clear error.
*/
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/ee/tokenRefresh.ts` around lines 52 - 62, Update the top
docstring in tokenRefresh.ts to remove the outdated mention of deprecated env
vars: change the line that currently reads that refresh attempts use "client
credentials from the config file (or deprecated env vars)" to state they use
OAuth client credentials from the config file only; ensure any other bullets in
the same comment no longer reference deprecated env vars so the docstring
accurately reflects the removed fallback.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In `@packages/backend/src/ee/tokenRefresh.ts`:
- Around line 52-62: Update the top docstring in tokenRefresh.ts to remove the
outdated mention of deprecated env vars: change the line that currently reads
that refresh attempts use "client credentials from the config file (or
deprecated env vars)" to state they use OAuth client credentials from the config
file only; ensure any other bullets in the same comment no longer reference
deprecated env vars so the docstring accurately reflects the removed fallback.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 14ff19a4-9283-4e79-9b87-a8c834bd0b71

📥 Commits

Reviewing files that changed from the base of the PR and between cfab0cf and 014d1b4.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/tokenRefresh.ts
  • packages/shared/src/env.server.ts
  • packages/web/src/ee/features/sso/sso.ts
💤 Files with no reviewable changes (2)
  • packages/web/src/ee/features/sso/sso.ts
  • packages/shared/src/env.server.ts

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
docs/docs/upgrade/v4-to-v5-guide.mdx (1)

186-186: ⚡ Quick win

Break this paragraph into shorter chunks.

This paragraph contains 5 sentences. As per coding guidelines, documentation should prefer short paragraphs (1-3 sentences) to improve readability. Consider breaking this into 2-3 shorter paragraphs to align with the guideline.

♻️ Suggested restructuring
-In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file. Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen. This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.+In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file.++Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen.++This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/docs/upgrade/v4-to-v5-guide.mdx` at line 186, The paragraph about
deprecation of AUTH_EE_* env vars should be split into two or three shorter
paragraphs to improve readability: first, state that AUTH_EE_* (e.g.,
AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the identityProviders
config section; second, explain that starting in v5.0.2 the env var path was
removed and Sourcebot no longer reads those vars; and optionally add a third
short sentence noting that upgrades from v5.0.0 or v5.0.1 are affected if
providers were only configured via those env vars. Keep each paragraph to 1–3
sentences and preserve the references to AUTH_EE_*, identityProviders, and
v5.0.2.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@docs/docs/upgrade/v4-to-v5-guide.mdx`:
- Line 186: The paragraph about deprecation of AUTH_EE_* env vars should be
split into two or three shorter paragraphs to improve readability: first, state
that AUTH_EE_* (e.g., AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the
identityProviders config section; second, explain that starting in v5.0.2 the
env var path was removed and Sourcebot no longer reads those vars; and
optionally add a third short sentence noting that upgrades from v5.0.0 or v5.0.1
are affected if providers were only configured via those env vars. Keep each
paragraph to 1–3 sentences and preserve the references to AUTH_EE_*,
identityProviders, and v5.0.2.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 9a29743a-acff-4895-ab84-3f55dfe2cb34

📥 Commits

Reviewing files that changed from the base of the PR and between 014d1b4 and 89dbcd5.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • docs/docs/upgrade/v4-to-v5-guide.mdx
✅ Files skipped from review due to trivial changes (1)
  • CHANGELOG.md

@brendan-kellam
brendan-kellam merged commit d2843aa into mainJun 10, 2026
9 of 10 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/remove-deprecated-sso-env-vars branch June 10, 2026 16:25
@github-actionsgithub-actionsBot mentioned this pull request Jun 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore: remove deprecated env-var identity provider configuration - #1297

Merged
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars
Jun 10, 2026
Merged

chore: remove deprecated env-var identity provider configuration#1297
brendan-kellam merged 7 commits into
mainfrom
bkellam/remove-deprecated-sso-env-vars

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Summary

Removes support for configuring identity providers via the deprecated AUTH_EE_* environment variables for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID. These providers must now be configured through the identityProviders section of the config file, which is already a complete replacement (every one of these providers is supported there).

GCP IAP is intentionally unaffectedAUTH_EE_GCP_IAP_ENABLED and AUTH_EE_GCP_IAP_AUDIENCE remain supported (they're also read in layout.tsx / onboard/page.tsx to drive the IAP bridge sign-in). AUTH_EE_ALLOW_EMAIL_ACCOUNT_LINKING is also untouched (it's a behavioral flag, not a provider credential).

Changes

  • packages/web/src/ee/features/sso/sso.ts — removed the deprecated env-var provider blocks from the identityProviders.length == 0 path (kept GCP IAP).
  • packages/backend/src/ee/tokenRefresh.ts — removed getDeprecatedEnvCredentials and its fallback in refreshOAuthToken; token refresh now relies solely on config-file provider credentials.
  • packages/shared/src/env.server.ts — removed the deprecated AUTH_EE_{GITHUB,GITLAB,GOOGLE,OKTA,KEYCLOAK,MICROSOFT_ENTRA_ID}_* env var declarations.

Breaking change

Deployments configuring any of the six providers via AUTH_EE_* environment variables must migrate to the identityProviders config-file section. No functionality is lost — only the configuration mechanism changes.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Breaking Changes

    • Removed support for configuring GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID via deprecated AUTH_EE_* environment variables. These providers must be configured in the config file’s identityProviders section; providers still configured only via env vars will stop appearing on the login screen. GCP IAP env vars remain supported.
  • Documentation

    • Upgrade guide updated with migration steps, examples, and a GitHub config example.

Removes support for configuring GitHub, GitLab, Google, Okta, Keycloak, and
Microsoft Entra ID identity providers via the deprecated AUTH_EE_*_CLIENT_ID/
SECRET/etc. environment variables. These providers must now be defined through
the identityProviders section of the config file. GCP IAP env vars
(AUTH_EE_GCP_IAP_ENABLED / AUTH_EE_GCP_IAP_AUDIENCE) are unaffected.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a150cfa-3476-4776-a4c7-88ca95465523

📥 Commits

Reviewing files that changed from the base of the PR and between 89dbcd5 and 0cc3bb8.

📒 Files selected for processing (1)
  • CHANGELOG.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • CHANGELOG.md

Walkthrough

This PR removes deprecated AUTH_EE_* identity-provider environment variables from the server schema, removes env-var fallback from token refresh and SSO initialization, and adds a breaking-change note and upgrade guidance directing users to the config file identityProviders section.

Changes

Remove deprecated OAuth environment variable fallback

Layer / File(s)Summary
Environment schema removal
packages/shared/src/env.server.ts
The deprecated AUTH_EE_* identity provider environment variable block is removed from the server schema, eliminating all legacy OAuth provider credential definitions for GitHub, GitLab, Google, Okta, Keycloak, and Microsoft Entra ID.
Token refresh and SSO cleanup
packages/backend/src/ee/tokenRefresh.ts, packages/web/src/ee/features/sso/sso.ts
The getDeprecatedEnvCredentials helper is removed and refreshOAuthToken now logs an error and returns null instead of falling back to deprecated env vars when no provider config exists; SSO initialization no longer constructs providers from env.AUTH_EE_* variables when config providers are empty.
Changelog and upgrade guide updates
CHANGELOG.md, docs/docs/upgrade/v4-to-v5-guide.mdx
A breaking-change note documents the removal of AUTH_EE_* environment variable support and the upgrade guide adds migration steps and examples to move provider configuration into the config file identityProviders array.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#841: Directly modifies the token refresh back-compat flow by adding the deprecated AUTH_EE_* env-variable fallback that this PR removes.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: removal of deprecated environment variable-based identity provider configuration.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/remove-deprecated-sso-env-vars

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 3 commits June 9, 2026 20:49
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/ee/tokenRefresh.ts (1)

52-62: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Update docstring to remove outdated reference to deprecated env vars.

Line 57 still mentions that token refresh attempts use "client credentials from the config file (or deprecated env vars)." Since this PR removes the deprecated env-var fallback, the docstring should be updated.

📝 Proposed fix
 /**
* Ensures the OAuth access token for a given account is fresh.
*
* - If the token is not expired (or has no expiry), decrypts and returns it as-is.
* - If the token is expired or near expiry, attempts a refresh using the OAuth
- * client credentials from the config file (or deprecated env vars).+ * client credentials from the config file.
* - On successful refresh: persists the new tokens to the DB, clears any
* tokenRefreshErrorMessage, and returns the fresh access token.
* - On failure: sets tokenRefreshErrorMessage on the account and throws, so
* the calling job fails with a clear error.
*/
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/ee/tokenRefresh.ts` around lines 52 - 62, Update the top
docstring in tokenRefresh.ts to remove the outdated mention of deprecated env
vars: change the line that currently reads that refresh attempts use "client
credentials from the config file (or deprecated env vars)" to state they use
OAuth client credentials from the config file only; ensure any other bullets in
the same comment no longer reference deprecated env vars so the docstring
accurately reflects the removed fallback.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In `@packages/backend/src/ee/tokenRefresh.ts`:
- Around line 52-62: Update the top docstring in tokenRefresh.ts to remove the
outdated mention of deprecated env vars: change the line that currently reads
that refresh attempts use "client credentials from the config file (or
deprecated env vars)" to state they use OAuth client credentials from the config
file only; ensure any other bullets in the same comment no longer reference
deprecated env vars so the docstring accurately reflects the removed fallback.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 14ff19a4-9283-4e79-9b87-a8c834bd0b71

📥 Commits

Reviewing files that changed from the base of the PR and between cfab0cf and 014d1b4.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • packages/backend/src/ee/tokenRefresh.ts
  • packages/shared/src/env.server.ts
  • packages/web/src/ee/features/sso/sso.ts
💤 Files with no reviewable changes (2)
  • packages/web/src/ee/features/sso/sso.ts
  • packages/shared/src/env.server.ts

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
docs/docs/upgrade/v4-to-v5-guide.mdx (1)

186-186: ⚡ Quick win

Break this paragraph into shorter chunks.

This paragraph contains 5 sentences. As per coding guidelines, documentation should prefer short paragraphs (1-3 sentences) to improve readability. Consider breaking this into 2-3 shorter paragraphs to align with the guideline.

♻️ Suggested restructuring
-In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file. Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen. This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.+In v4, you could configure these identity providers using `AUTH_EE_*` environment variables (for example `AUTH_EE_GITHUB_CLIENT_ID`). Those variables were deprecated in favor of the [`identityProviders`](/docs/configuration/idp) section of the config file.++Starting in v5.0.2, the environment variable path has been removed. Sourcebot no longer reads these variables, and any provider configured only through them will stop appearing on the login screen.++This also applies if you are upgrading from an earlier v5 release (v5.0.0 or v5.0.1), where these variables were still supported.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/docs/upgrade/v4-to-v5-guide.mdx` at line 186, The paragraph about
deprecation of AUTH_EE_* env vars should be split into two or three shorter
paragraphs to improve readability: first, state that AUTH_EE_* (e.g.,
AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the identityProviders
config section; second, explain that starting in v5.0.2 the env var path was
removed and Sourcebot no longer reads those vars; and optionally add a third
short sentence noting that upgrades from v5.0.0 or v5.0.1 are affected if
providers were only configured via those env vars. Keep each paragraph to 1–3
sentences and preserve the references to AUTH_EE_*, identityProviders, and
v5.0.2.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@docs/docs/upgrade/v4-to-v5-guide.mdx`:
- Line 186: The paragraph about deprecation of AUTH_EE_* env vars should be
split into two or three shorter paragraphs to improve readability: first, state
that AUTH_EE_* (e.g., AUTH_EE_GITHUB_CLIENT_ID) were deprecated in favor of the
identityProviders config section; second, explain that starting in v5.0.2 the
env var path was removed and Sourcebot no longer reads those vars; and
optionally add a third short sentence noting that upgrades from v5.0.0 or v5.0.1
are affected if providers were only configured via those env vars. Keep each
paragraph to 1–3 sentences and preserve the references to AUTH_EE_*,
identityProviders, and v5.0.2.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 9a29743a-acff-4895-ab84-3f55dfe2cb34

📥 Commits

Reviewing files that changed from the base of the PR and between 014d1b4 and 89dbcd5.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • docs/docs/upgrade/v4-to-v5-guide.mdx
✅ Files skipped from review due to trivial changes (1)
  • CHANGELOG.md

@brendan-kellam
brendan-kellam merged commit d2843aa into mainJun 10, 2026
9 of 10 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/remove-deprecated-sso-env-vars branch June 10, 2026 16:25
@github-actionsgithub-actionsBot mentioned this pull request Jun 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam