Gateway sign-in endpoints return a flat 404 when no identity provider is configured.
What's wrong with this entry?
On the self-hosted gateway, POST /oauth/device_authorization and POST /oauth/token now answer with a plain 404 not found when the OIDC identity-provider config is absent, before any rate-limiting or form parsing. Previously the handlers ran regardless.
- This matches the discovery document, which already omitted both endpoints unless OIDC config was present.
- The guard reads a config precondition; the exact config key it checks is not fully pinned down in the build.
/oauth/device_authorization
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.227
claude gatewaynow identifies itself as the gateway providerBoth mention gateway
-
v2.1.229
Gateway streaming keeps connections alive with pings
Both mention gateway
-
v2.1.232
Cloud gateway sign-in explains its restart, and refuses when it cannot
Both mention gateway