Map membership, profile, and inactive-user failures from OpenOIDCChildSessionForOrganization to a generic 404 instead of 500 so org-scoped OIDC callbacks do not reveal tenant access details. Signed-off-by: Bryan Frimin <bryan@probo.com>
Map membership, profile, and inactive-user failures from OpenOIDCChildSessionForOrganization to a generic 404 instead of 500 so org-scoped OIDC callbacks do not reveal tenant access details. Signed-off-by: Bryan Frimin <bryan@probo.com>