Skip to content

docs: document public https URL requirement for org SSO#700

Open
mintlify[bot] wants to merge 1 commit into
mainfrom
mintlify/sso-public-url-validation
Open

docs: document public https URL requirement for org SSO#700
mintlify[bot] wants to merge 1 commit into
mainfrom
mintlify/sso-public-url-validation

Conversation

@mintlify
Copy link
Copy Markdown
Contributor

@mintlify mintlify Bot commented May 25, 2026

Summary

Documents a new save-time validation rule applied to organization-managed SSO configurations: provider URLs the Lightdash backend has to fetch (Okta domain, Generic OIDC discovery document) must be public https:// URLs.

Changes

  • Added a "URL requirements for organization-managed SSO" section to the SSO providers reference page covering the validated fields per provider, the rejection rules (localhost, loopback, private/internal networks), an example error response, and a note that the check runs only at save time (existing stored configs and self-hosted env-based configs are unaffected).

Context

Triggered by lightdash/lightdash#23476, which adds SSRF protection by validating that org-admin-supplied Okta domains and OIDC discovery URLs resolve to public addresses before they are fetched server-side during issuer discovery. Azure AD is unaffected because its endpoints are templated.

cc @ the PR author from the upstream change — please review.

@mintlify
Copy link
Copy Markdown
Contributor Author

mintlify Bot commented May 25, 2026

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated (UTC)
lightdash 🟢 Ready View Preview May 25, 2026, 7:21 PM

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 25, 2026

🤖 Documentation Bot

Status

⚠️ 1 broken link needs manual attention


🔗 Broken Links (Manual Fix Required)

Click to view details
   📄 timezones-draft.mdx

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants