Add a B2B organizations section to the staff dashboard (staff UI 4/4) - #3997
Open
blarghmatey wants to merge 3 commits into
Open
blarghmatey wants to merge 3 commits into
blarghmatey wants to merge 3 commits into
Conversation
blarghmatey
added this pull request to stack #3998
September 19, 2026 01:28
OpenAPI ChangesShow/hide changesUnexpected changes? Ensure your branch is up-to-date with |
blarghmatey
marked this pull request as ready for review
September 19, 2026 01:30
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Valid pasted XML can be rendered incorrectly, and the mapping removal control is inaccessible by keyboard.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Adds staff-dashboard workflows for managing B2B organizations, onboarding, identity providers, and provisioning history.
Changes:
- Adds organization list, create, edit, and detail views.
- Adds SAML/OIDC provisioning and lifecycle controls.
- Adds onboarding state and audit-history interfaces.
| File | Description |
|---|---|
App.tsx |
Registers routes, resources, and staff access. |
interfaces/index.d.ts |
Defines provisioning API types. |
components/b2b/constants.ts |
Defines states, transitions, and resources. |
components/b2b/identity_providers.tsx |
Displays and manages identity providers. |
components/b2b/onboarding_card.tsx |
Manages onboarding state. |
components/b2b/organization_form.tsx |
Provides shared organization fields. |
components/b2b/provisioning_events.tsx |
Displays provisioning history. |
components/b2b/use_refresh_organization.ts |
Invalidates provisioning queries. |
pages/b2b_organizations/create.tsx |
Adds organization creation. |
pages/b2b_organizations/edit.tsx |
Adds minimal organization updates. |
pages/b2b_organizations/identity_provider_create.tsx |
Adds SAML/OIDC creation workflow. |
pages/b2b_organizations/index.ts |
Exports organization pages. |
pages/b2b_organizations/list.tsx |
Adds searchable organization listing. |
pages/b2b_organizations/show.tsx |
Adds organization detail view. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
blarghmatey
force-pushed
the
b2b-staff-ui-orgs-sso
branch
2 times, most recently
from
September 25, 2026 18:16
fe831f5 to
4e3f3a4
Compare
Onboarding a B2B partner's organization and SSO today means a reviewed Pulumi PR against ol-infrastructure, and the C1 provisioning API has had no operator surface. This adds one for CS/ops staff, over the provisioning routes and the list, SP details and change history added earlier in this stack. - Organizations: a filterable list with onboarding state and each IdP's lifecycle state, create, and edit. Edit sends only the fields that changed: Keycloak can hold a null redirect URL, which the update endpoint rejects, and any domains sent are rewritten as verified. org_key is only sent on create. An organization without SSO is a normal case and shows an empty IdP table. - Onboarding: the current state, when it changed, and a form to record a new state with notes. Nothing gates on it. - Identity providers: add a SAML (metadata URL or pasted XML) or OIDC (discovery URL and client credentials) IdP. SAML mappings match an attribute by FriendlyName or by Name. "Check what Keycloak reads" calls parse-metadata and shows the parsed config before anything is created. Each IdP has the allowed lifecycle moves (draft, testing, active, disabled) behind a confirmation, metadata refresh, delete, and the SP entity ID, ACS URL and SP metadata URL to hand to the partner. - Change history: the provisioning audit events, newest first, with the before and after data. The section is open to is_staff users, not only superusers, matching the API's IsAdminUser permission. There is no test-login button yet. Nothing in MITx Online passes kc_idp_hint through to Keycloak today, so moving an IdP to testing still needs an operator to build that login URL by hand. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VcbiSRu3CsE4uyfr6Lqjdr
…emoval a button A pasted metadata document can start with whitespace, which the backend strips before detecting XML, so the IdP details showed the whole document as its source. The remove-mapping control was a bare icon that keyboard users could not reach; it is now a labelled button. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VcbiSRu3CsE4uyfr6Lqjdr
lifecycle_state comes from the API, so a state added on the backend before IDP_ALLOWED_TRANSITIONS learns it would crash the organization page on .map of undefined. It now renders with "Move to" disabled. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VcbiSRu3CsE4uyfr6Lqjdr
blarghmatey
force-pushed
the
b2b-staff-ui-orgs-sso
branch
from
September 25, 2026 19:39
4e3f3a4 to
b36b0e7
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What are the relevant tickets?
Phase 2 of the B2B onboarding RFC, https://github.com/mitodl/hq/discussions/12784: the staff UI for orgs and SSO over C1. We retire the per-org Pulumi path once we're confident provisioning through this UI works.
Stack (4 of 4). Based on 3/4. It uses the list, SP details and change history that 1/4 adds to the provisioning API.
Description (What does it do?)
Today, onboarding a partner's organization and SSO means a reviewed Pulumi PR against
olapps.py, and the C1 provisioning API has no operator surface. This adds a B2B Organizations section to the staff dashboard for CS/ops.org_keyis only sent on create. An org without SSO is a normal case and shows an empty IdP table.attribute_map/attribute_name_map).parse-metadataand shows the parsed config before anything is created.The section is open to
is_staffusers, not only superusers, which matches the API'sIsAdminUser. Per the 2026-09-18 decision, there's no approval step before an IdP goes active. The change history is the control.Not in this PR:
kc_idp_hintthrough to Keycloak yet, so testing an IdP still needs a hand-built login URL.How can this be tested?
tsc --noEmitis clean and the production build passes. I drove the section in headless Chromium against an in-memory mock of 1/4's API shapes. No page errors, and the request bodies matched the serializers. The flows:?l=25&o=0&q=...)descriptionNot yet run against a real backend and Keycloak. In the QA environment, as a staff user:
🤖 Generated with Claude Code
https://claude.ai/code/session_01VcbiSRu3CsE4uyfr6Lqjdr