Skip to content

fix(auth): open regional OAuth on the site host - #868

Merged
platinummonkey merged 1 commit into
mainfrom
fix/regional-oauth-host
Sep 29, 2026
Merged

platinummonkey merged 1 commit into
mainfrom
fix/regional-oauth-host

Conversation

@platinummonkey

Copy link
Copy Markdown
Collaborator

What does this PR do?

OAuth login for regional sites now opens the authorize page on the site host itself (https://us3.datadoghq.com/oauth2/v1/authorize), instead of app.{site}.

app. is kept only for the bare UI sites: datadoghq.com, datadoghq.eu, datad0g.com, and ddog-gov.com. API hosts are unchanged (api.us3.datadoghq.com).

Motivation

On US3, app.us3.datadoghq.com and us3.datadoghq.com are different browser sessions. SAML (Entra ID) posts the response to us3, which rejects it with an invalid InResponseTo. The same host layout applies to US5, AP1, AP2, and any other non-bare subdomain.

Additional Notes

GovCloud stays on app.ddog-gov.com. Bits and ACP use the same host helper, so they follow these UI hosts too.

Checklist

  • The code change follows the project conventions (see CONTRIBUTING.md)
  • Tests have been added/updated (if applicable)
  • Documentation has been updated (if applicable)
  • All CI checks pass
  • Code coverage is maintained or improved

Related Issues

Closes #855

Made with Cursor

US3, US5, AP1, and AP2 serve the UI on the site host, not app.{site}.
Prefixing app. sends SAML login to a different browser session than the
assertion consumer, which Datadog rejects. Keep app. only for the bare
UI sites.

Co-authored-by: Cursor <cursoragent@cursor.com>
@platinummonkey
platinummonkey requested a review from a team as a code owner September 28, 2026 16:39

@datadog-datadog-prod-us1-2 datadog-datadog-prod-us1-2 Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bits Code Review: PASS

More details

Regional sites now use their site host for OAuth authorization while API routing and bare-site app. hosts remain unchanged; no actionable regression was identified.

Was this helpful? React 👍 or 👎

Open Bits AI session

🤖 Bits Code Review · Commit 422e481 · @DataDog review to ask questions

@srosenthal-dd srosenthal-dd left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! I did several local tests on a build from the branch and confirmed logins still work as expected on SAML and Google Login, for sites with and without custom subdomains, and sites with and without the app prefix.

@platinummonkey
platinummonkey merged commit 514e9ef into main Sep 29, 2026
6 checks passed
@platinummonkey
platinummonkey deleted the fix/regional-oauth-host branch September 29, 2026 12:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] auth login fails with SAML error on US3 because authorize URL uses app.us3.datadoghq.com

3 participants