Back to releases
v0.7.6

OIDC login and single-tenant mode (v0.7.6)

OIDC login, JIT user creation, external-identity binding, and single-tenant auto-join ship, rounding out the enterprise onboarding path.

OIDCAuthenticationEnterprise deployment

Langhuan can now connect to external identity providers: users can sign in through OIDC, get created automatically on first login, and complete profile gaps or bind an external identity when needed. Enterprise teams no longer have to maintain an isolated password portal just to use Langhuan.

The OIDC login path

The sign-in flow forms a complete loop from provider config, through a Redis state store, to the HTTP callback:

  • OIDC profiles without an email are supported; necessary details are filled in on a complete-profile page.
  • Existing accounts can bind an external identity, so a repeat login doesn’t accidentally create a second user.
  • OIDC and password modes are controlled by runtime config, so deployments can choose what to open up per environment.
  • Login, JIT creation, merge, and binding are all orchestrated by the application service; the HTTP handler only does protocol translation.

Single-tenant mode

For deployments that serve a single team, single-tenant mode limits the workspace count and lets new users auto-join the only workspace after first login. The console also hides the creation entry points that don’t apply, reducing the options an admin has to explain.

More careful access boundaries

A user who’s already bound won’t re-enter the binding flow, and a deleted member won’t be silently restored by a fresh JIT login. When profile validation fails, only desensitized diagnostic info is logged, keeping identity fields out of logs.