Skip to content

make sure pre saml login is enabled after saml is disabled - #13953

Open
DaanHoogland wants to merge 2 commits into
mainfrom
ghi12595-saml-disable-ldap-fallback
Open

DaanHoogland wants to merge 2 commits into
mainfrom
ghi12595-saml-disable-ldap-fallback

Conversation

@DaanHoogland

@DaanHoogland DaanHoogland commented Aug 22, 2026 •

Copy link
Copy Markdown
Contributor

Description

This PR...

Fixes: #12595

  • On enabling SAML, the user's current Source is now saved (via the generic user_details key/value store, UserDetailsDao — the same mechanism UserPasswordResetManagerImpl and the OAuth2 login command already use) before it gets overwritten to SAML2. Skipped if already SAML2/SAML2DISABLED (nothing meaningful to remember), and guarded against a null source (an edge case I found via the pre-existing test).
  • On disabling SAML with enable.login.with.disabled.saml=true, it now restores that saved source (e.g. LDAP) via a new getPreSamlSource helper, instead of hardcoding UNKNOWN. Falls back to UNKNOWN if nothing was ever recorded (pre-existing users from before this fix) or the stored value is unrecognized.

Types of changes

  • Breaking change (fix or feature that would cause existing functionality to change)
  • New feature (non-breaking change which adds functionality)
  • Bug fix (non-breaking change which fixes an issue)
  • Enhancement (improves an existing feature and functionality)
  • Cleanup (Code refactoring and cleanup, that may add test cases)
  • Build/CI
  • Test (unit or integration test code)

Feature/Enhancement Scale or Bug Severity

Feature/Enhancement Scale

  • Major
  • Minor

Bug Severity

  • BLOCKER
  • Critical
  • Major
  • Minor
  • Trivial

Screenshots (if appropriate):

How Has This Been Tested?

How did you try to break this feature and the system with this change?

@codecov

codecov Bot commented Aug 22, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 61.29032% with 12 lines in your changes missing coverage. Please review.
✅ Project coverage is 19.73%. Comparing base (5e5ae0c) to head (08f943d).
⚠️ Report is 91 commits behind head on main.

Files with missing lines Patch % Lines
...g/apache/cloudstack/saml/SAML2AuthManagerImpl.java 61.29% 10 Missing and 2 partials ⚠️
Additional details and impacted files
@@             Coverage Diff              @@
##               main   #13953      +/-   ##
============================================
+ Coverage     19.72%   19.73%   +0.01%     
- Complexity    19941    19961      +20     
============================================
  Files          6371     6371              
  Lines        575738   575802      +64     
  Branches      70471    70479       +8     
============================================
+ Hits         113582   113656      +74     
+ Misses       449810   449792      -18     
- Partials      12346    12354       +8     
Flag Coverage Δ
uitests 3.41% <ø> (ø)
unittests 21.01% <61.29%> (+0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions

github-actions Bot commented Aug 22, 2026 •

Copy link
Copy Markdown

🔴 Test Coverage Grade: D — Marginal

Metric Value
Line coverage 24.61%
Branch coverage 18.82%

Grade Scale

Grade Line Coverage Meaning
🟢 A ≥ 80% Excellent - this code sleeps well at night 😴
🟡 B 60-79% Good - almost there, don't stop now 😉
🟠 C 40-59% Acceptable - your code is wearing a seatbelt, but no airbags 😬
🔴 D 20-39% Marginal - boldly shipping where no test has gone before 🖖
⛔ F < 20% Failing - tests? what tests? 🔥

Branch coverage is shown as a secondary signal. Grade is determined by line coverage.
View full Actions run

@sonarqubecloud

Copy link
Copy Markdown

@kiranchavala

Copy link
Copy Markdown
Member

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@kiranchavala a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19161

@kiranchavala kiranchavala left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@DaanHoogland

Issue is present

  1. Configure LDAP server . add a ldap account

  2. Log in as the ldap user

(localcloud) 🐱 > list users username=kiran listall=true filter=username,id,usersource
⣷ 😸 trying to log in...
{
  "count": 1,
  "user": [
    {
      "id": "ad5e867e-5ce2-43e0-ac4c-3c5450f8f8ca",
      "username": "kiran",
      "usersource": "ldap"
    }
  ]
}

  1. Ldap login succesfull

  2. Configure saml on the ldap user

(localcloud) 🐱 > list users username=kiran listall=true filter=username,id,usersource
{
  "count": 1,
  "user": [
    {
      "id": "ad5e867e-5ce2-43e0-ac4c-3c5450f8f8ca",
      "username": "kiran",
      "usersource": "saml2"
    }
  ]
}

  1. Saml login successfull

  2. Disable Saml authentication on the user

(localcloud) 🐱 > list users username=kiran listall=true filter=username,id,usersource
{
  "count": 1,
  "user": [
    {
      "id": "ad5e867e-5ce2-43e0-ac4c-3c5450f8f8ca",
      "username": "kiran",
      "usersource": "saml2disabled"
    }
  ]
}

  1. Unable to login with ldap
mysql> select * from user_details;
+----+---------+---------------+-------+---------+
| id | user_id | name          | value | display |
+----+---------+---------------+-------+---------+
|  2 |       5 | PreSamlSource | LDAP  |       1 |
+----+---------+---------------+-------+---------+
1 row in set (0.00 sec)
  1. logs
2026-09-15 10:48:28,138 DEBUG [c.c.a.ApiServlet] (qtp1151704483-16:[ctx-c49d6da0]) (logid:a8550e5c) ===START===  10.0.3.251 -- POST   login
2026-09-15 10:48:28,138 DEBUG [c.c.a.ApiSessionListener] (qtp1151704483-16:[ctx-c49d6da0]) (logid:a8550e5c) Session created by Id : node0tjykvf1cdsxl1kne3qnrxnejw9 , session: Session@add86b1{id=node0tjykvf1cdsxl1kne3qnrxnejw9,x=node0tjykvf1cdsxl1kne3qnrxnejw9.node0,req=1,res=true} , source: Session@add86b1{id=node0tjykvf1cdsxl1kne3qnrxnejw9,x=node0tjykvf1cdsxl1kne3qnrxnejw9.node0,req=1,res=true} , event: javax.servlet.http.HttpSessionEvent[source=Session@add86b1{id=node0tjykvf1cdsxl1kne3qnrxnejw9,x=node0tjykvf1cdsxl1kne3qnrxnejw9.node0,req=1,res=true}]
2026-09-15 10:48:28,142 DEBUG [c.c.u.AccountManagerImpl] (qtp1151704483-16:[ctx-c49d6da0]) (logid:a8550e5c) Attempting to log in user: kiran in domain 1
2026-09-15 10:48:28,143 DEBUG [c.c.u.AccountManagerImpl] (qtp1151704483-16:[ctx-c49d6da0]) (logid:a8550e5c) Unable to authenticate user with username kiran in domain 1
2026-09-15 10:48:28,144 DEBUG [c.c.u.AccountManagerImpl] (qtp1151704483-16:[ctx-c49d6da0]) (logid:a8550e5c) User: kiran in domain 1 has failed to log in
2026-09-15 10:48:28,555 DEBUG [c.c.a.ApiSessionListener] (qtp1151704483-16:[ctx-c49d6da0]) (logid:a8550e5c) Session destroyed by Id : node0tjykvf1cdsxl1kne3qnrxnejw9 , session: Session@add86b1{id=node0tjykvf1cdsxl1kne3qnrxnejw9,x=node0tjykvf1cdsxl1kne3qnrxnejw9.node0,req=1,res=true} , source: Session@add86b1{id=node0tjykvf1cdsxl1kne3qnrxnejw9,x=node0tjykvf1cdsxl1kne3qnrxnejw9.node0,req=1,res=true} , event: javax.servlet.http.HttpSessionEvent[source=Session@add86b1{id=node0tjykvf1cdsxl1kne3qnrxnejw9,x=node0tjykvf1cdsxl1kne3qnrxnejw9.node0,req=1,res=true}]
2026-09-15 10:48:28,556 DEBUG [c.c.a.ApiServlet] (qtp1151704483-16:[ctx-c49d6da0]) (logid:a8550e5c) Authentication failure: {"loginresponse":{"uuidList":[],"errorcode":531,"errortext":"Failed to authenticate user kiran in domain 1; please provide valid credentials"}}
2026-09-15 10:48:28,556 DEBUG [c.c.a.ApiServlet] (qtp1151704483-16:[ctx-c49d6da0]) (logid:a8550e5c) ===END===  10.0.3.251 -- POST   login

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: Ready

Development

Successfully merging this pull request may close these issues.

Ldap imported accounts which are saml enabled doesn't fallback to ldap if saml is disabled

3 participants