apache / apache/cloudstack

NullPointerException in ApiServlet.skip2FAcheckForUser for SAML SSO sessions when 2FA is not enabled

Ouverte
#13,815 0 commentaires 0 réactions 0 personnes assignées Réclamée par @DaanHoogland Voir sur GitHub
bug component:authentication
Langage dominant
Java
Étoiles
3.1k
Forks
1.4k
Merge moyen
6 j 19 h
PR mergées (30 j)
32

Description

### problem

`ApiServlet.skip2FAcheckForUser(HttpSession)` unboxes the `IS_2FA_VERIFIED` session attribute without a null check (ApiServlet.java:512):

```java
boolean is2FAverified = (boolean) session.getAttribute(ApiConstants.IS_2FA_VERIFIED);
```

For sessions established via SAML SSO, this attribute is never set on the `HttpSession`. `getAttribute` returns `null`, unboxing to `boolean` throws a `NullPointerException`, and the API response write aborts with an empty 200 body. The UI then fails at `permission.js` (`GenerateRoutes`) and renders a blank page. This happens even though 2FA is not enabled anywhere in the environment.

Server-side error:

ERROR [c.c.a.ApiServlet] unknown exception writing api response
java.lang.NullPointerException: Cannot invoke "java.lang.Boolean.booleanValue()"
because the return value of "javax.servlet.http.HttpSession.getAttribute(String)" is null
at com.cloud.api.ApiServlet.skip2FAcheckForUser(ApiServlet.java:512)
at com.cloud.api.ApiServlet.processRequestInContext(ApiServlet.java:362)
at com.cloud.api.ApiServlet$1.run(ApiServlet.java:194)

### versions

CloudStack: 4.22.1.0
Config: saml2.enabled=true; two-factor authentication NOT enabled (no enable.2fa configuration present)
IdP: Microsoft Entra ID (SAML 2.0)
OS: EL8.10
DB: MariaDB 10.5
Management server behind Apache httpd reverse proxy (443 -> 8443)

### The steps to reproduce the bug

1. Configure SAML SSO (saml2.enabled=true), with 2FA NOT enabled.
2. Log in as a SAML user via SSO.
3. Continue using the session until an API call reaches skip2FAcheckForUser (e.g. listUsers during UI bootstrap on a session that has aged).
4. The API returns an empty 200 body; the UI renders a blank page.

Expected: SAML sessions without 2FA proceed normally and the API returns a valid response.
Actual: NullPointerException at ApiServlet.java:512, empty response, blank UI.

### What to do about it?

Suggested fix:
- Null-safe read at ApiServlet.java:512, e.g.:
boolean is2FAverified = Boolean.TRUE.equals(session.getAttribute(ApiConstants.IS_2FA_VERIFIED));
- Additionally, set IS_2FA_VERIFIED on the session in the SAML login path (SAML2LoginAPIAuthenticatorCmd) as the standard username/password login path does, so SAML sessions carry the attribute.

Workaround for operators:
- Delete the JSESSIONID cookie and re-authenticate via SSO to establish a fresh session (confirmed working).

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Commencez par ApiServlet.java:512 et le chemin de connexion SAML dans SAML2LoginAPIAuthenticatorCmd, en comparant la manière dont le chemin standard nom d’utilisateur/mot de passe définit IS_2FA_VERIFIED. Reproduisez le scénario d’une session SAML ancienne et vérifiez que l’API renvoie une réponse valide sans NullPointerException et que l’UI ne s’affiche plus vide.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
java
Domaine
api, authentication, backend
Type d'issue
Bug
Difficulté
3/5
Temps estimé
1-2 jours
Activité
À l'abandon
Clarté
Clairement spécifiée
Accessibilité débutants
35/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.