dcd0b4ebcdaad30dc9d87c78a31c13c219240cd9
The roles-claim and default-roles fallback paths in applyClaimMappings were using assignRoleToUser (origin='direct'), causing OIDC-derived roles to accumulate across logins and never be cleared. Changed both to assignManagedRole (origin='managed') so all OIDC-assigned roles are cleared and re-evaluated on every login, same as claim mapping rules. Only roles assigned directly via the admin UI are preserved. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Description
Observability server for Cameleer agents
Languages
Java
61.6%
TypeScript
30.2%
HTML
5.2%
CSS
2.9%