2 Commits
Author SHA1 Message Date
jknapp c68d72857f Merge pull request 'docs: note that Entra keys identity on oid, not sub' (#25) from docs/identity-keying-note into main 2026-08-13 02:40:44 +00:00
shadowdaoandClaude Opus 5 391d8e0360 docs: note that Entra keys identity on oid, not sub
The Architecture section still described identity as keyed on `sub` + `iss`,
which stopped being universally true when 0005_user_oid.sql landed. It is
still correct for Authentik, Keycloak and Okta — but on Entra, `sub` is
pairwise per app registration and `oid` is the key. Someone reading only
this section would draw exactly the wrong conclusion about why a second
account appeared.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 19:40:31 -07:00
+4 -2
View File
@@ -37,8 +37,10 @@ Workspace. Anything that publishes a `/.well-known/openid-configuration`.
The same container serves both the MCP endpoint (under `/api/mcp`) and the
Web UI. Users authenticate via your OIDC provider with pre-registered
confidential clients. Identity is keyed on the OIDC `sub` + `iss` so
memories are scoped per user.
confidential clients. Identity is keyed on the OIDC `iss` + `sub` so memories
are scoped per user — except on Microsoft Entra ID, where `sub` is pairwise
(a different value per app registration for the same person) and `oid` is
used instead. See [`docs/oidc-entra-id.md`](docs/oidc-entra-id.md) §7.
---