From 9bf1021a30f4830fbbcc20d269608084e5e1831a Mon Sep 17 00:00:00 2001 From: Kay Joosten Date: Thu, 17 Sep 2026 14:46:19 +0200 Subject: [PATCH 1/2] fix: point dev logout redirect at local test SP instead of surf.nl config/openconext/parameters.yaml.dist is the local-development default config: every other URL in it (gateway, middleware, SAML endpoints) points at *.dev.openconext.local, but logout_redirect_url was still hardcoded to the public www.surf.nl production pages. This forced OpenConext-devconf's stepup docker-compose stack to bind-mount a full 95-line replacement parameters.yaml just to override this one key, duplicating and needing to stay in sync with this dist file. Fixing the default here lets devconf drop that override, matching how gateway/ middleware/ra already work with no devconf-side config file. en_GB and nl_NL now both redirect to the local test SP (ssp.dev.openconext.local), consistent with the rest of this file. --- config/openconext/parameters.yaml.dist | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/config/openconext/parameters.yaml.dist b/config/openconext/parameters.yaml.dist index a870501c..338bb4a2 100644 --- a/config/openconext/parameters.yaml.dist +++ b/config/openconext/parameters.yaml.dist @@ -47,8 +47,8 @@ parameters: stepup_loa_self_asserted: 'http://dev.openconext.local/assurance/loa1.5' logout_redirect_url: - nl_NL: https://www.surf.nl/over-surf/werkmaatschappijen/surfnet - en_GB: https://www.surf.nl/en/about-surf/subsidiaries/surfnet + nl_NL: https://ssp.dev.openconext.local/simplesaml/sp.php + en_GB: https://ssp.dev.openconext.local/simplesaml/sp.php enabled_second_factors: - sms From 4e1e36768e0b73cdb73e27c78ba32f16f53ad4be Mon Sep 17 00:00:00 2001 From: Kay Joosten Date: Thu, 17 Sep 2026 14:50:59 +0200 Subject: [PATCH 2/2] ci: rebuild :test docker image on every push to main The build-push-test-docker-image workflow's trigger was left pointing at feature/build-and-publish-test-container, a branch that is already merged. Since then it can only run via manual workflow_dispatch and never rebuilds on a normal merge to main, so the :test image silently goes stale (the same issue found and fixed in OpenConext/Stepup-Gateway#666). Trigger the workflow on push to main instead, so the :test tag stays in sync with the default branch going forward. --- .github/workflows/build-push-test-docker-image.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/build-push-test-docker-image.yml b/.github/workflows/build-push-test-docker-image.yml index 67429e70..8a542717 100644 --- a/.github/workflows/build-push-test-docker-image.yml +++ b/.github/workflows/build-push-test-docker-image.yml @@ -2,7 +2,8 @@ name: build-push-test-docker-image on: push: - branches: feature/build-and-publish-test-container + branches: + - main workflow_dispatch: jobs: