mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 03:01:21 +02:00
Without it every account auto-created through the env provider fell back to Viewers (routes/mfa.py), and because the provider is locked the UI could not correct it either -- a real limitation for a declarative deployment running BAMBUDDY_OIDC_AUTO_CREATE_USERS=true. BAMBUDDY_OIDC_DEFAULT_GROUP names a group rather than an id: ids are handed out per installation, so the same compose file would point at a different group on the next deployment. The name is matched exactly, resolved against the database before anything is written, and default_group_id joins _APPLIED_FIELDS so dropping the variable clears the group again -- the environment is the whole truth for this row. A name that matches no group is refused rather than defaulted: silently landing users in Viewers is the failure this variable exists to remove, and the API already answers 422 for a default_group_id that does not exist. The refusal is logged and survivable, and it says which of the two cases happened, because they differ sharply -- an existing provider keeps running on its last good config, while on a first boot nothing is created and no SSO button appears. Raised by maziggy in review of #2625 as a scope decision; documented in .env.example and in the companion wiki PR.