pub async fn get_deploy_callback(
configuration: &Configuration,
) -> Result<(), Error<GetDeployCallbackError>>Expand description
Completes the redirect from IAM: it validates state against the single-use flow cookie in constant time, redeems the authorization code with the PKCE verifier, and then VERIFIES the resulting token exactly as this deployment’s identity boundary will on every later request — so a token that would be refused next request fails here with the real reason instead of producing a sign-in loop. On success it sets the session cookie, bounded by the token’s own expiry, and redirects to the validated return path. It fails closed, and closes on the ADMIN ORG: a principal whose verified owner claim is not the reserved admin org is told plainly that it lacks the role (403) and no cookie is minted for it. That check is not the authorization decision — every gated route re-derives SuperAdmin from the verified JWT — it exists so nobody is handed a session that silently 403s everything. No flow in progress, or a mismatched state, is a 400; a refused or unexchangeable code is a 401.