Admins can force gateway login using forceLoginMethod or forceLoginGatewayUrl in managed settings.
What's wrong with this entry?
Administrators can now require gateway login from managed policy settings: it applies when forceLoginMethod is "gateway", or when forceLoginGatewayUrl is set and no method is named.
- Managed policy settings are the admin-controlled settings file that overrides user and project settings.
- The org-enforcement path's fail-closed branch now triggers whenever policy settings are missing and load errors are present, not only when the org identifier is absent; it still reports
policy_unreadable_fail_close.
forceLoginGatewayUrl
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.225
Untrusted-device recovery can be turned off by a flag; unarchive gets its own 403 handling
Both mention login auth
-
v2.1.234
Clearer error when an Anthropic profile login has expired
Both mention login auth
-
v2.1.242
/login asks how you want to sign in to a Console account
Both mention login auth