docs: document session management and OIDC state transfer #5329
+465
−0
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Context
Documents the Redis-backed session architecture used for OIDC and OAuth authentication flows. Answers: What handles server sessions? How is organization slug preserved across IDP redirects?
Key points:
@fastify/session+connect-rediswith 10min TTLorgSlug→ Redis session → callback retrieval → config lookup → session destructionFiles added:
backend/docs/SESSION_MANAGEMENT.md- Complete architecture, flows, security modelbackend/docs/SESSION_QUICK_REFERENCE.md- Quick lookup for common questionsbackend/docs/README.md- Documentation indexExample from OIDC flow:
Screenshots
N/A
Steps to verify the change
Review documentation in
backend/docs/directory.Type
Checklist
type(scope): short description(scope is optional, e.g.,fix: prevent crash on syncorfix(api): handle null response).✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.