Skip to content

feat: add organization flags to auth0 apps create and update - #1690

Merged
ramya18101 merged 3 commits into
mainfrom
feat/apps-organization-flags
Sep 29, 2026
Merged

ramya18101 merged 3 commits into
mainfrom
feat/apps-organization-flags

Conversation

@developerkunal

Copy link
Copy Markdown
Contributor

🔧 Changes

Adds three flags to auth0 apps create and auth0 apps update so an application's organization behavior can be configured directly, without dropping to the raw auth0 api command:

  • --organization-usage — deny, allow, or require
  • --organization-require-behavior — no_prompt, pre_login_prompt, or post_login_prompt
  • --organization-discovery-methods — comma-separated list of email, organization_name

The flags are additive and non-breaking, and follow the existing optional-flag pattern used by --third-party-security-mode and --redirection-policy:

  • On create, each field is sent only when the flag is provided.
  • On update, a field is sent only when its flag is set, so unset flags never clobber existing values.

Example:

auth0 apps create --name myapp --type regular \
  --organization-usage require \
  --organization-require-behavior pre_login_prompt \
  --organization-discovery-methods email,organization_name

🔬 Testing

Verified end-to-end against a live tenant: create sends all three fields; update of an unrelated field preserves org values; updating a single org field changes only that field; invalid values and the API's pre_login_prompt dependency surface as clean 400 errors. Existing unit tests pass via make test-unit, and docs were regenerated with make docs.

📝 Checklist

  • All new/changed/fixed functionality is covered by tests (or N/A)
  • I have added documentation for all new/changed functionality (or N/A)

Add --organization-usage, --organization-require-behavior, and
--organization-discovery-methods to auth0 apps create and update,
so an application's organization behavior can be configured without
dropping to the raw api command. The flags are additive and follow
the existing optional-flag pattern: create sets each when provided,
update only sends a field when its flag is set so unset flags never
clobber existing values.
@developerkunal
developerkunal requested a review from a team as a code owner September 28, 2026 04:29
Add table-driven tests for the organization flag mapping on apps create
and update, and validate client-side that --organization-discovery-methods
is only used with --organization-require-behavior=pre_login_prompt so a
misconfiguration returns an actionable error instead of a server 400.
Gate the create org fields on flag presence to match update.
- Drop the client-side organization-require-behavior requires organization-usage=require
  check; the Management API accepts any usage, or none, alongside any require behavior
- Keep the one real cross-field rule: organization-discovery-methods requires
  organization-require-behavior=pre_login_prompt
- Strip empty organization-discovery-methods entries before sending
- Run organization flag validation before the network read and interactive prompts
- Render organization fields in apps show output
- Update require-behavior help text and regenerate docs
@ramya18101
ramya18101 merged commit e0e4823 into main Sep 29, 2026
6 checks passed
@ramya18101
ramya18101 deleted the feat/apps-organization-flags branch September 29, 2026 18:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants