Skip to content

docs: unlisted auth schemes pass through on coordinators without SSO - #1792

Merged
vpavicic merged 1 commit into
release/3.14from
docs/coord-unlisted-scheme-passthrough
Oct 2, 2026
Merged

vpavicic merged 1 commit into
release/3.14from
docs/coord-unlisted-scheme-passthrough

Conversation

@as51340

@as51340 as51340 commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Release note

On a high availability coordinator, a Bolt authentication scheme that is not listed in --auth-module-mappings now takes the same passthrough path as basic/none instead of being rejected as unsupported. With no SSO module configured it is accepted with credentials ignored (the 3.12 behavior); once SSO is configured it is denied under the same license and writable-role conditions as basic auth, with a message naming the scheme.

Documented on the coordinator authentication page:

  • Rewrote Authentication modes as a two-path rule (listed SSO scheme vs. everything else) and dropped the standalone "unsupported scheme" rejection.
  • Renamed Basic authentication passthrough to Authentication passthrough and extended it to unlisted schemes, with both denial messages and a 3.13 → 3.14 callout.
  • Generalized the break-glass, license-loss, and follower-without-quorum sections from "basic auth" to "passthrough".
  • Small wording alignment for SHOW CURRENT USER / SHOW CURRENT ROLE on the HA commands reference.

Related product PRs

Checklist:

  • Add appropriate milestone (current release cycle)
  • Add bugfix or feature label, based on the product PR type you're documenting
  • Make sure all relevant tech details are documented
    • Update reference pages (no flag, clause or function changes)
    • Search for the feature you are working on (mentions) and make updates if needed
    • Provide a basic example of usage
    • In case your feature is an Enterprise one, list it under ME page and mark its page with Enterprise (page already marked Enterprise)
  • Check all content with Grammarly
  • Perform a self-review of my code
  • The build passes locally
  • My changes generate no new warnings or errors

Document memgraph/memgraph#4962: on a coordinator, any Bolt scheme not
listed in --auth-module-mappings now takes the same passthrough path as
basic/none instead of being rejected outright. Describe the two-path
rule, the per-scheme denial messages once SSO is configured, and the
3.13 -> 3.14 behavior change.
@as51340 as51340 added this to the 3.14 milestone Sep 29, 2026
@as51340 as51340 added the bugfix Documentation related to a product bugfix label Sep 29, 2026
@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
documentation Ready Ready Preview Sep 29, 2026 9:39am UTC

Request Review

@vpavicic
vpavicic merged commit bda49f3 into release/3.14 Oct 2, 2026
2 checks passed

This branch was successfully deployed

1 active deployment
Preview — cc40eba8 Deployed Sep 29, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Documentation related to a product bugfix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants