Google OIDC and GitHub OAuth identify users by provider and stable subject ID. Matching email addresses do not merge identities or grant administrator access. The first verified identity atomically becomes the administrator. Configure one provider and complete the owner's first sign-in before enabling other providers or promoting the site.
The site setting Allow other users to sign in or register defaults to off. Administrators may still sign in. Rejected users receive no profile or session; existing non-administrator sessions and personal API keys also lose access. Anonymous reading of explicitly public repositories remains available. Administrators can edit both language notices; the refusal page returns to a validated local reading page after five seconds.
The initial service origin is https://context4ai-sourcegraph.fly.dev.
- Google:
https://context4ai-sourcegraph.fly.dev/sourcegraph/auth/google/callback - GitHub:
https://context4ai-sourcegraph.fly.dev/sourcegraph/auth/github/callback
Use the same origin in SOURCEGRAPH_ORIGIN. When the portal becomes the public entry point, update this setting and the provider callbacks together. For the planned custom domain, use https://context4ai.org/sourcegraph/auth/google/callback and https://context4ai.org/sourcegraph/auth/github/callback.
- Create or select a project in Google Cloud Console. Configure Google Auth Platform branding, audience and contact details.
- Create an OAuth client with application type Web application.
- Add the Google callback above as an authorized redirect URI. The service uses
openid,profileandemailscopes. - If the consent screen is in testing mode, add the administrator's Google account as a test user.
- Store the client ID and secret as
GOOGLE_CLIENT_IDandGOOGLE_CLIENT_SECRETin Fly Secrets. Redeploy/restart and sign in.
Google's web application guide
- In GitHub developer settings, open OAuth Apps → New OAuth App. This is user login, not a GitHub Actions OIDC setup.
- Use the demo service URL as Homepage URL and the GitHub callback above as Authorization callback URL.
- Generate a client secret and store
GITHUB_CLIENT_IDandGITHUB_CLIENT_SECRETin Fly Secrets. - Redeploy/restart, then sign in with the owner account. Only the
read:userscope is requested; repository access credentials remain separate.
Use the Fly dashboard Secrets UI, or fly secrets import --app context4ai-sourcegraph with a private input stream. Do not paste secrets into chat, commit them, or leave them in shell history. If both providers are configured, the first one used owns the administrator account; the other provider creates a distinct identity and is subject to registration policy.
The sign-in screen follows the site language and theme. With no configured provider it explains the missing Google/GitHub configuration and links to this setup guide; configured providers appear as sign-in buttons. A failed provider lookup offers retry without blocking the public browsing link. Login preserves the requested local Source Graph page.
Registration denial is a separate, server-rendered HTTP 403 page with the configured bilingual notice, a project link, and a five-second return to the validated previous page. This is distinct from missing OAuth configuration and provider lookup failures.