Skip to content

feat(auth): add organization creation control plane slice - #902

Merged
XiaoSeS merged 3 commits into
mainfrom
feature/enterprise-login-r1b2-org-admin
Sep 24, 2026
Merged

XiaoSeS merged 3 commits into
mainfrom
feature/enterprise-login-r1b2-org-admin

Conversation

@XiaoSeS

@XiaoSeS XiaoSeS commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

What

  • Add POST /api/v1/admin/organizations for SUPER_ADMIN to create an Organization with an existing eligible initial owner.
  • Atomically create the Organization, active manual Membership, ORG_OWNER binding, and success audit.
  • Generate and commit OpenAPI client types; document this isolated R1-B slice in OpenSpec.

Why

The merged read-only Organization API cannot yet bootstrap a tenant for subsequent member and Login Connection work. This is intentionally limited to organization creation: no directory sync, SCIM, enterprise login, member management, or UI.

How

  • Tenant access remains membership-gated. Platform admin status alone grants no tenant access.
  • Existing V61 schema is reused; no migration.
  • Owner must exist and be active, not a system or merged account.

Testing

  • Full backend suite: 1028 tests, 0 failures/errors, 1 skipped. Run before final operationId/test-only addition.
  • Final-head PlatformOrganizationControllerTest: 4 tests, 0 failures/errors/skips.
  • Web typecheck and lint, OpenSpec strict validation, and git diff --check passed.
  • OpenAPI schema generated from current application test context and checked in.
  • make staging NOT RUN locally: shared ports and services are occupied; compose lifecycle could affect unrelated environments. Final-head CI E2E (Real Services) is the isolated full-stack regression gate. The new endpoint is covered by targeted Spring integration tests.

Impact and review boundary

  • New platform-admin-only API; existing login routes and provider behavior unchanged.
  • Existing Organizations and data remain intact on rollback.
  • Organization/Membership APIs are independent of enterprise OIDC flags. A later connection-management slice will use SKILLHUB_ENTERPRISE_OIDC_ENABLED only for OIDC connection configuration/testing/activation; the login flag controls anonymous data-plane entry. This PR implements neither flag.

Review status

  • The Organization/OIDC boundary is decided and recorded in the overall and slice OpenSpec; both pass strict validation. Existing authorization code requires no change.
  • Default local make staging remains unrun to avoid disrupting shared services. Final-head Server/Web/E2E CI is required before merge; targeted endpoint integration tests have passed.

Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
@XiaoSeS
XiaoSeS marked this pull request as ready for review September 24, 2026 06:51
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
@XiaoSeS
XiaoSeS merged commit 455cbb5 into main Sep 24, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant