docs(v2): OIDC discovery_url + claims_mapping and Azure AD B2C guide - #413
Conversation
…D B2C guide Add documentation for the new per-provider OIDC options: - discovery_url: fetch the discovery document from a URL that differs from the token issuer (needed for Azure AD B2C, whose issuer is a tenant GUID while discovery is served from a policy-specific tenant-domain URL). - claims_mapping: JSON Pointer map for extracting user attributes from non-standard claims (e.g. B2C's emails array). Also adds a Login with Azure AD B2C guide covering setup and common pitfalls, updates the config reference table, and registers the guide in the nav. Signed-off-by: Ahmed Refaey <ahmed.refaey@scale.com> Co-authored-by: Cursor <cursoragent@cursor.com>
…rl-claims-mapping * origin/main: chore: add automated PR review workflow (flipt-io#417) docs(v2): document OIDC single logout (SLO) support (flipt-io#415) docs: add MCP server docs for v2 (flipt-io#416) # Conflicts: # docs/v2/configuration/authentication.mdx # docs/v2/configuration/overview.mdx
There was a problem hiding this comment.
Verdict: approve
Looks good — no changes requested. The PR accurately documents the new discovery_url and claims_mapping OIDC options and adds a well-structured Azure AD B2C login guide: required frontmatter present, code blocks language-tagged, the new page registered in docs.json, and all internal anchor links (#oidc, #discovery-url, #claims-mapping, #email-matches) resolve. Every config key referenced in the guide (use_pkce, fetch_extra_user_info, email_matches, redirect_address, ${env:...} substitution, session.domain/secure) matches existing v2 docs. The only change since the prior approving review is the v2.12.0 → v2.13.0 placeholder bump in the overview table, still an acknowledged placeholder pending the paired flipt-io/flipt code change.
🤖 Automated review by the Flipt PR review agent.
Signed-off-by: Roman Dmytrenko <rdmytrenko@gmail.com>
Overview
Documents the two new per-provider OIDC options and adds a dedicated Azure AD B2C login guide. This pairs with an upcoming change in
flipt-io/fliptthat addsdiscovery_urlandclaims_mappingto the OIDC auth method.Why
Azure AD B2C is OIDC-compliant but has two behaviors that break the generic
oidcmethod today:issuerit reports (and puts in theissclaim) is the tenant GUID. The standard OIDC issuer check then fails.emailsarray rather than a stringemailclaim, soemail_matcheshas nothing to match against.Changes
v2/configuration/authentication.mdxdiscovery_url(fetch discovery from one URL, verify tokens againstissuer_url).claims_mapping(JSON Pointer extraction ofemail/name/picture/sub).v2/configuration/overview.mdx— addeddiscovery_urlandclaims_mappingrows to the OIDC config reference table.v2/guides/operations/authentication/login-with-azure-ad-b2c.mdx— new guide covering app registration, finding the issuer vs discovery URLs, a fullconfig.yml, and a troubleshooting section (404 discovery, issuer mismatch,email_matchesneeding claim mapping).docs.json— registered the new guide in the Authentication nav group..vale/styles/Flipt/spelling-exceptions.txt— addedb2candguid.Notes
vale/mint devlocally (deps not installed); prettier (2.8.8) was run on the changed files.Made with Cursor