diff --git a/frontend/src/__tests__/components/OIDCProviderSettings.test.tsx b/frontend/src/__tests__/components/OIDCProviderSettings.test.tsx
index 1436b7e20..91d35eaa4 100644
--- a/frontend/src/__tests__/components/OIDCProviderSettings.test.tsx
+++ b/frontend/src/__tests__/components/OIDCProviderSettings.test.tsx
@@ -361,6 +361,25 @@ describe('env-managed provider (#2593)', () => {
expect(screen.queryByTestId('delete-provider-2')).not.toBeInTheDocument();
});
+ it('offers no icon controls for it either', async () => {
+ server.use(
+ http.get('/api/v1/auth/oidc/providers/all', () =>
+ HttpResponse.json([
+ { ...envManagedProvider, icon_url: 'https://idp.example.com/i.png', has_icon: true },
+ ])
+ )
+ );
+ render();
+
+ await waitFor(() => {
+ expect(screen.getByText('EnvIdP')).toBeInTheDocument();
+ });
+ // Both icon routes answer 409 for an env-managed provider, so a click could
+ // only ever produce an error toast — the same reason the rest are hidden.
+ expect(screen.queryByTestId('refresh-icon-2')).not.toBeInTheDocument();
+ expect(screen.queryByTestId('remove-icon-2')).not.toBeInTheDocument();
+ });
+
it('still offers them for a UI-created provider', async () => {
server.use(
http.get('/api/v1/auth/oidc/providers/all', () =>
@@ -375,4 +394,25 @@ describe('env-managed provider (#2593)', () => {
expect(screen.getByTestId('edit-provider-1')).toBeInTheDocument();
expect(screen.getByTestId('delete-provider-1')).toBeInTheDocument();
});
+
+ it('hides the enable/disable toggle for env-managed providers', async () => {
+ server.use(
+ http.get('/api/v1/auth/oidc/providers/all', () =>
+ HttpResponse.json([
+ { ...mockProviders[0], id: 2, name: 'EnvIdP', is_enabled: true, is_env_managed: true },
+ { ...mockProviders[0], id: 3, name: 'UiIdP', is_enabled: true, is_env_managed: false },
+ ])
+ )
+ );
+ render();
+
+ await waitFor(() => {
+ expect(screen.getByText('EnvIdP')).toBeInTheDocument();
+ expect(screen.getByText('UiIdP')).toBeInTheDocument();
+ });
+ // The toggle carries no testid, so it is counted: two cards are rendered and
+ // exactly one switch may exist — the UI provider's. Enabling the env-managed
+ // one would be reverted by the next boot, and the API answers 409.
+ expect(screen.getAllByRole('switch')).toHaveLength(1);
+ });
});
diff --git a/frontend/src/components/OIDCProviderSettings.tsx b/frontend/src/components/OIDCProviderSettings.tsx
index 6ec27aca9..a9ade30c5 100644
--- a/frontend/src/components/OIDCProviderSettings.tsx
+++ b/frontend/src/components/OIDCProviderSettings.tsx
@@ -398,35 +398,36 @@ export function OIDCProviderSettings() {
- {provider.icon_url && (
-
- )}
- {provider.has_icon && (
-
- )}
{/* #2593: startup rewrites the env-managed row from BAMBUDDY_OIDC_*
- and the API answers 409, so offering these would promise a
- change that cannot land. */}
+ and the API answers 409, so offering any of these would promise
+ a change that cannot land -- the icon routes included, where the
+ click only ever produced an error toast. */}
{!provider.is_env_managed && (
<>
+ {provider.icon_url && (
+
+ )}
+ {provider.has_icon && (
+
+ )}
toggleEnabled(provider)}