From aa7e984e305ea96acfd1592320aaedeb96c6ad83 Mon Sep 17 00:00:00 2001 From: Khaleel Al-Adhami Date: Tue, 28 Apr 2026 13:24:21 -0700 Subject: [PATCH] add notice to use reflex enterprise --- README.md | 37 +++++++++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) diff --git a/README.md b/README.md index fba4858..2dbd665 100644 --- a/README.md +++ b/README.md @@ -1,5 +1,42 @@ # reflex-okta-auth +> **This repository is archived.** Use the OIDC support built into the +> `reflex-enterprise` package instead. +> +> Notably, this package stores tokens in `LocalStorage`, which is readable by +> any script running on the page (e.g. via XSS). The `reflex-enterprise` OIDC +> state stores tokens in HttpOnly, `Secure`, `SameSite=Strict` cookies, and +> additionally provides refresh tokens with cross-tab sync, nonce / `at_hash` +> validation, and granted-scope tracking. Functionally, anything this package +> does is also covered there. +> +> ### Migrating +> +> Subclass `OIDCAuthState` with `__provider__ = "okta"` — the same +> `OKTA_CLIENT_ID`, `OKTA_CLIENT_SECRET`, and `OKTA_ISSUER_URI` env vars are +> picked up automatically (config lookup is `{PROVIDER}_*`): +> +> ```python +> import reflex as rx +> from reflex_enterprise.auth.oidc.state import OIDCAuthState +> +> class OktaAuthState(OIDCAuthState, rx.State): +> __provider__ = "okta" +> ``` +> +> Render the login button — endpoints are registered automatically on first +> use, so no explicit `register_auth_endpoints(app)` call is needed: +> +> ```python +> OktaAuthState.get_login_button("Log In with Okta") +> ``` +> +> Logout (`redirect_to_logout`) and `userinfo` keep the same names and shape. + +--- + +## Legacy usage (deprecated) + This package requires the `reflex_enterprise` package to be installed. ## Installation