* If the domain has SSO configured, returns a WorkOS response. * Returns null if no SSO is configured or if WorkOS organization lookup fails.
( domain: string, warningContext: Record<string, unknown> )
| 116 | { status: 503 } |
| 117 | ); |
| 118 | } |
| 119 | } |
| 120 | |
| 121 | /** |
| 122 | * If the domain has SSO configured, returns a WorkOS response. |
| 123 | * Returns null if no SSO is configured or if WorkOS organization lookup fails. |
| 124 | */ |
| 125 | async function tryGetSSOResponse(domain: string): Promise<NextResponse | null> { |
| 126 | const authority = await resolveSsoAuthorityForDomain(domain); |
| 127 | if (authority.status === 'not_required') { |
| 128 | return null; |
| 129 | } |
| 130 | if (authority.status === 'misconfigured') { |
| 131 | warnInSentry('Local SSO authority is misconfigured', { |
| 132 | extra: { domain, reason: authority.reason }, |
| 133 | }); |
| 134 | return NextResponse.json( |
| 135 | { error: 'Unable to find sign-in methods. Please try again.' }, |
| 136 | { status: 503 } |
| 137 | ); |
| 138 | } |
| 139 | |
| 140 | const organization = await getWorkOSOrganization(domain); |
| 141 | if (organization) { |
| 142 | return discoveryResponse({ kind: 'sso', organizationId: organization.id }); |
| 143 | } |
| 144 | |
| 145 | // DB says SSO exists but WorkOS doesn't have it - this is a config error |
| 146 | warnInSentry('Local organization has SSO but WorkOS organization not found', { |
| 147 | extra: { domain, localOrgId: authority.sourceOrganizationId }, |
| 148 | }); |
| 149 | return NextResponse.json( |
| 150 | { error: 'Unable to find sign-in methods. Please try again.' }, |
| 151 | { status: 503 } |
no test coverage detected