fix(tooling): close the last Access and Google guidance gaps - #51
Merged
Merged
Conversation
Add the remaining owner-verified facts to the bootstrap guide text (packages/cli/src/lib/platform/guides.mjs) and the production how-to so both stay complete: - Every guide that opens Cloudflare and chooses the LVBT account now says to check the account switcher and rename the account if it still shows the old, misspelled name. - The Google Workspace identity provider guide now says to turn PKCE back off only if Test fails with a code-verifier error, and to skip service account keys and domain-wide delegation when creating the OAuth client. - The Access application guide now says not to add a Country rule. - The Google Group guide now checks an existing group's join and external-member settings before relying on it, not only a newly created one, and its offboarding step now also revokes the Cloudflare One session immediately instead of waiting for the next sign-in. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TL;DR
The bootstrap and production how-to guides for Cloudflare Access and Google Workspace were missing a
handful of facts the owner verified live while setting the platform up: checking and fixing the
Cloudflare account's name, a PKCE troubleshooting fallback, skipping service account keys, skipping
Access country rules, and two Google Group checks. This fills every one of those gaps in the source
of truth repository, so every repository that copies from it gets the complete guidance.
Overview of Changes
packages/cli/src/lib/platform/guides.mjsprints the click-by-click steps thatlvbt bootstrap --productionandlvbt preflightshow in a terminal. Five gaps against the owner's verified notesare closed there and mirrored in
docs/how-to/set-up-production.md, which is the same guidance forsomeone reading ahead instead of running the command:
check the account switcher and rename the account if it still shows the old, misspelled name,
instead of assuming the account is already named correctly.
come off if the later "Test" step fails with a code-verifier error, and it now tells the reader to
skip service account keys and domain-wide delegation while creating the OAuth client, since nothing
in this setup uses either.
lock out anyone signing in while travelling for little real protection.
existing group's "Who can join" and "Allow external members" settings before the setup relies on
it, because those are the two settings that would otherwise quietly let the wrong people in.
only removing them from the group and waiting for their current session to expire.
No behavior outside the printed guide text changed.
pnpm checkpasses, including the existing testthat every guide pastes each copied value before asking for the next.
Follow-ups
None. This closes the guidance gaps identified in this review; no further guidance work is known to
be outstanding on this repository.
🤖 Generated with Claude Code