docs: note that Entra keys identity on oid, not sub

The Architecture section still described identity as keyed on `sub` + `iss`,
which stopped being universally true when 0005_user_oid.sql landed. It is
still correct for Authentik, Keycloak and Okta — but on Entra, `sub` is
pairwise per app registration and `oid` is the key. Someone reading only
this section would draw exactly the wrong conclusion about why a second
account appeared.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-08-12 19:40:31 -07:00
co-authored by Claude Opus 5
parent bd7a1ca59a
commit 391d8e0360
+4 -2
View File
@@ -37,8 +37,10 @@ Workspace. Anything that publishes a `/.well-known/openid-configuration`.
The same container serves both the MCP endpoint (under `/api/mcp`) and the
Web UI. Users authenticate via your OIDC provider with pre-registered
confidential clients. Identity is keyed on the OIDC `sub` + `iss` so
memories are scoped per user.
confidential clients. Identity is keyed on the OIDC `iss` + `sub` so memories
are scoped per user — except on Microsoft Entra ID, where `sub` is pairwise
(a different value per app registration for the same person) and `oid` is
used instead. See [`docs/oidc-entra-id.md`](docs/oidc-entra-id.md) §7.
---