Show an existing NetKingdom sign-in before the account site continues it.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Build and Publish Container Image / build-and-push (push) Successful in 19s
Account journey acceptance / journeys (push) Successful in 8s

The account site said "Not signed in" while Authelia still had a session, and Sign in reused that identity. Ask Authelia who the session cookie is, show that name, and send a fresh sign-in only when a different identity is requested.

Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
This commit is contained in:
tegwick 2026-09-27 00:21:34 +02:00
parent b987a3de9e
commit 560cdeed46
9 changed files with 500 additions and 19 deletions

View file

@ -21,6 +21,12 @@ class OIDCClientTests(unittest.TestCase):
self.assertIn(query["state"][0], self.client.pending)
self.assertNotIn(self.client.pending[query["state"][0]].verifier, url.query)
def test_fresh_begin_asks_for_a_new_sign_in_without_raising_assurance(self):
query = parse_qs(urlparse(self.client.begin(fresh=True)).query)
self.assertEqual(["login"], query["prompt"])
self.assertEqual(["0"], query["max_age"])
self.assertNotIn("acr_values", query)
def test_begin_can_forward_a_tenant_hint_without_changing_session_authority(self):
url = urlparse(self.client.begin(tenant_hint="tenant:friendly:binky"))
self.assertEqual(