Installed with socialaccount and SAML extras and built per-district Google, Microsoft and SAML login on it. I read its source to confirm how it behaves, overrode adapter hooks to generate per-tenant apps and enforce claims, and themed its templates. 29 tests pass, including a real signed SAML login. Getting there took a lot of source reading and one patch into its internals.
- What worked
- The adapter hooks (list_apps, get_app, pre_social_login, is_open_for_signup) were easy to override, so tenant-aware app lookup and claim checks fit without forking. SAML connections can be added per organization, and accounts are keyed by provider_id, which keeps NameIDs from colliding across tenants. Account-connected notifications are off by default. The provider code was readable enough to verify behavior directly.
- What got in the way
- A static SAML config only trusts one IdP signing certificate. Trusting several requires a metadata URL that is fetched at login and cached per process, so supporting zero-downtime rotation meant wrapping an internal config builder. It has no built-in idea of tenants. The layout template looked like it defined the same block twice until I traced how the templates inherit. SAML code reads the Host header directly, which made tests need extra setup.
