mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 19:21:33 +02:00
apply_env_oidc_provider matches the provider by BAMBUDDY_OIDC_NAME but never cleared is_env_managed from the row it managed previously. Renaming the variable therefore left two flagged rows, and both consequences are reachable by ordinary config edits: the old row stayed enabled with a stale issuer and secret on the login page while _refuse_if_env_managed answered 409 to every attempt to edit, disable or delete it -- the dead end reachable only through the database that the release path exists to prevent -- and unsetting the variables later hit scalar_one_or_none() on two rows, so MultipleResultsFound propagated out of the lifespan and the app stopped booting. The upsert now sweeps the flag off every other row, the same shape the autologin sweep one block down already uses: disable and release rather than delete, for the same cascade reason as everywhere else in this branch. The release path releases every flagged row it finds instead of exactly one -- the sweep should keep that at one, but a release path that dies with MultipleResultsFound the moment that invariant breaks is a second way to lose the boot, and the query costs the same either way. Releasing now clears is_autologin as well. Without it a released row keeps a latent autologin claim: update_oidc_provider only re-runs the exclusivity sweep when a request sets is_autologin=True, so merely re-enabling the row in the UI would silently make it the autologin target again. Reported by maziggy in review of #2625, with the rename reproduction.