apache / apache/cloudstack

Global setting oauth2.plugins

オープン
#13,862 コメント 1 件 リアクション 0 件 担当者 1 名 @Damans227 が担当を希望しています GitHub で見る
bug
主要言語
Java
スター
3.1k
フォーク
1.4k
平均マージ
6日 19時間
マージ済み PR(30日)
32

説明

### problem

Is the global value of oauth2.plugins referenced or enforced anywhere in the code ?

### versions

ACS 4.22
ACS 4.23 rc 2

### The steps to reproduce the bug

oauth2.plugins (default "google,github", described as "List of OAuth plugins") is declared but is it used anywhere for validation ation.

Actual provider availability is determined entirely by which Spring beans exist (GoogleOAuth2Provider, GithubOAuth2Provider, hardcoded in the XML) plus oauth2.plugins.exclude (see Issue #2) and a different key, user.oauth2.providers.order, for ordering.

Steps to Reproduce:
1. cmk list configurations name=oauth2.plugins — shows google,github.
2. cmk update configuration name=oauth2.plugins value=github,keycloak

3. Attempt OAuth2 login with provider=google.

### What to do about it?

Expected: GitHub provider no longer available, per the setting's name and description.
Actual: No error on update, but github remains fully registered and functional — the change is a complete no-op.

Suggested fix: Either wire oauth2.plugins to genuinely gate provider registration, or remove it — as-is it presents a non-functional control surface that could lead an admin to believe they've disabled a provider when they haven't.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。