getsentry / getsentry/sentry

Honor Relay State URL for Post-SAML Sign-in Redirection

Open
#94,833 2 comments 1 reaction 0 assignees View on GitHub
Auth Feature Product Area: Sign In
Dominant language
Python
Stars
44.8k
Forks
4.9k
Avg merge
21h 10m
Merged PRs (30d)
635

Description

### Problem Statement

Currently, when an end-user needs to sign into Sentry via SAML, the experience often requires them to follow a link or click a button on a Sentry page to initiate the authentication flow. This creates an extra step that can disrupt the end-user experience, especially in scenarios where only one IdP is configured and required for use.

Furthermore, while Sentry supports SAML, it's expected that the Relay State URL should also be honored to send the end-user to a specific page after the sign-in is successful.

### Solution Brainstorm

*No response*

### Product Area

Sign In

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are identified in the issue. Trace the SAML sign-in flow and its Relay State handling first, then define the expected post-sign-in redirect behavior and add coverage for sending the user to the requested URL after successful authentication.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
authentication
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.