lahirujayathilake opened a new pull request, #547:
URL: https://github.com/apache/airavata-custos/pull/547

   Accounts created by the identity provisioner could not be used: the cluster 
login name did not match the assigned username, sign-in over SSH failed, and a 
previously deleted registry person could be silently reused.
   
   
   ## What this does
   
   - People are created with their login identity and a verified email, the 
only point where the registry accepts them.
   - The person's uid identifier is set to the assigned username, so the 
directory maps the correct cluster login name.
   - An org identity carrying the user's OIDC subject is created and linked, 
matching what registry enrollment produces, so device-auth sign-in works.
   - The email lookup skips soft-deleted people, so re-provisioning an email 
creates a fresh person instead of reusing a dead record.
   
   Fixes #537


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to