apache / apache/cloudstack

Ldap imported accounts which are saml enabled doesn't fallback to ldap if saml is disabled

未关闭
#12,595 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
component:LDAP component:saml
主要语言
Java
星标
3.1k
派生
1.4k
平均合并
6 天 19 小时
30 天内合并 PR
32

描述

### problem

Ldap imported accounts which are saml enabled doesn't fallback to ldap if saml is disabled

### versions

ACS 4.23 Nightly

### The steps to reproduce the bug

1. Configure a LDAP and Import a LDAP account

Image

2. Check the user type , its set to LDAP

Image

3. Authorize SAML to the imported ldap account

Image

4. The user type is assigned as SAML

Image

5. Disable SAML SSO

Image

6. The user type is assigned as NATIVE TYPE

Image

7. The LDAP imported user is not able to login with LDAP credentials since the user type changes

made sure the setting

enable.login.with.disabled.saml is set to true

https://github.com/apache/cloudstack/pull/10868

### What to do about it?

If the SAML authentication is disabled for a LDAP imported account.

The user type should switch back to LDAP

贡献指南

打开贡献指南

调研方向

首先,复现 issue 中描述的 LDAP 导入、SAML 授权、SAML 禁用和 LDAP 登录步骤,然后阅读 PR #10868 中变更的行为。跟踪在禁用 SAML 时账户用户类型发生更改的位置。当账户恢复为 LDAP 用户类型,并且在所述设置启用的情况下能够使用 LDAP 凭据进行身份验证时,即表示完成。

由索引模型根据 Issue 内容生成。

评估

技术栈
java
领域
authentication
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
冷清
描述清晰度
基本清楚
新手友好度
52/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。