docs: note that Entra keys identity on oid, not sub
The Architecture section still described identity as keyed on `sub` + `iss`, which stopped being universally true when 0005_user_oid.sql landed. It is still correct for Authentik, Keycloak and Okta — but on Entra, `sub` is pairwise per app registration and `oid` is the key. Someone reading only this section would draw exactly the wrong conclusion about why a second account appeared. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -37,8 +37,10 @@ Workspace. Anything that publishes a `/.well-known/openid-configuration`.
|
|||||||
|
|
||||||
The same container serves both the MCP endpoint (under `/api/mcp`) and the
|
The same container serves both the MCP endpoint (under `/api/mcp`) and the
|
||||||
Web UI. Users authenticate via your OIDC provider with pre-registered
|
Web UI. Users authenticate via your OIDC provider with pre-registered
|
||||||
confidential clients. Identity is keyed on the OIDC `sub` + `iss` so
|
confidential clients. Identity is keyed on the OIDC `iss` + `sub` so memories
|
||||||
memories are scoped per user.
|
are scoped per user — except on Microsoft Entra ID, where `sub` is pairwise
|
||||||
|
(a different value per app registration for the same person) and `oid` is
|
||||||
|
used instead. See [`docs/oidc-entra-id.md`](docs/oidc-entra-id.md) §7.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user