Skip to content

Improve ClassLink auth option handling - #75710

Open
carl-codeorg wants to merge 3 commits into
stagingfrom
fix/classlink-options
Open

carl-codeorg wants to merge 3 commits into
stagingfrom
fix/classlink-options

Conversation

@carl-codeorg

Copy link
Copy Markdown
Contributor

ClassLink auth options are unique because we support two different versions. There are a couple of legit scenarios where users will have both: they pre-dated the v2 auth option migration, or their district originally didn't support OneRoster, then later turned it on. Users created for districts without OneRoster would have nil-version auth options, then after signing in with OneRoster support, they would get a v2 auth option. For these users we don't actually want to surface two auth options on the account settings page, since this is just one login method to the user. This PR does two things:

  • Changes the account settings page to only show a single row for ClassLink, even if the user has both nil-version and v2 auth options.
  • Makes disconnecting the ClassLink login remove both auth options. This avoids the nil-version auth options from popping back up after the v2 auth option is disconnected.

Before:
Screenshot 2026-10-01 at 1 34 49 PM

After:
Screenshot 2026-10-01 at 4 04 25 PM

Links

Functionality from PR #75478 will need to be updated to match once this is merged in.

Testing story

Deployment notes

Privacy and security

…2 options

A ClassLink user can hold two records for one identity: a v1 record keyed
by ClassLink's UserId and a v2 record keyed by "<TenantId>|<SourcedId>".
Sign-in keeps both on purpose, so users migrated to v2, or whose district
enabled OneRoster after they signed up, saw two "ClassLink Account" rows
under "Manage linked accounts".

Add Queries::User::LinkedAccounts, which lists one ClassLink record: the
newest v2, or the v1 when no v2 exists. The edit view uses it in place of
the raw options.

Since the listed row now stands for every ClassLink record, disconnecting
it removes all of them. Removing only the listed record would leave the
hidden one, so ClassLink would still show as connected and the next
sign-in would rebuild the v2 record. Primary contact replacement covers
the case where the hidden record was primary.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@carl-codeorg
carl-codeorg marked this pull request as ready for review October 2, 2026 04:12
@carl-codeorg
carl-codeorg requested a review from a team October 2, 2026 15:22
@nicklathe

Copy link
Copy Markdown
Contributor

Should we extend this to Clever too? We should have a bunch of teachers with v0/nil and v3 Clever auth options post Clever v3 migration that are in the same state, showing duplicated Clever linked accounts.

@carl-codeorg

Copy link
Copy Markdown
Contributor Author

Should we extend this to Clever too? We should have a bunch of teachers with v0/nil and v3 Clever auth options post Clever v3 migration that are in the same state, showing duplicated Clever linked accounts.

Yep this slipped by me. I thought we had removed the v0 Clever auth options, but this isn't the case. I'll modify this PR to include Clever.

carl-codeorg and others added 2 commits October 2, 2026 09:08
Clever is in the same position as ClassLink: a user migrated to the v3
API holds a pre-v3 record (nil version) alongside a v3 record, and both
showed as separate "Clever Account" rows under "Manage linked accounts".

Generalize Queries::User::LinkedAccounts over a table of providers and
their preferred version, with Clever preferring v3 as ClassLink prefers
v2. Disconnect uses the same table, so disconnecting the one Clever row
removes every Clever record the user holds.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The table lists providers whose records carry a version, and the
predicate asks whether a credential type is one of them, so name both
for that rather than for the collapsing they drive.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@carl-codeorg
carl-codeorg force-pushed the fix/classlink-options branch from e55a786 to d0bb668 Compare October 2, 2026 21:21

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants