From ccc90ff34c2c92c166e0731e4df946b2ec6efed5 Mon Sep 17 00:00:00 2001 From: Marian Date: Mon, 20 Jul 2026 14:38:28 +0000 Subject: [PATCH] feat(oidc): expose is_env_managed in the provider response The frontend needs it to render the provider read-only. Without the flag the UI would offer editable fields whose writes the API then refuses with 409 -- the change would look accepted right up until it wasn't. Refs #2593 --- backend/app/schemas/auth.py | 3 +++ 1 file changed, 3 insertions(+) diff --git a/backend/app/schemas/auth.py b/backend/app/schemas/auth.py index 597e03a1f..af604b1a1 100644 --- a/backend/app/schemas/auth.py +++ b/backend/app/schemas/auth.py @@ -518,6 +518,9 @@ class OIDCProviderResponse(BaseModel): icon_url: str | None = None default_group_id: int | None = None is_autologin: bool = False # #1589 + # #2593 — the UI renders this provider read-only; without the flag it would + # offer editable fields whose writes the API then refuses with 409. + is_env_managed: bool = False # Set explicitly in the route handler from `icon_content_type is not None` # rather than `@computed_field` (project policy) or `icon_data is not None` # (would trigger an async lazy-load on the deferred BLOB column).