apache / apache/cloudstack

LDAP Authentication: Malformed LDAP Filter Syntax, Authorization Works Only for Root Admin

オープン
#13,983 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
component:LDAP
主要言語
Java
スター
3.1k
フォーク
1.4k
平均マージ
6日 19時間
マージ済み PR(30日)
32

説明

### problem

## Issue Description

After upgrading CloudStack from version **4.21.0.0** to **4.22.1.0**, LDAP user authentication stopped working for all roles except **Root Admin**.

### Symptoms

1. **Root Admin** — authentication succeeds, UI works correctly
2. **Non-Root Admin users** — authentication appears to succeed, but after login:
- System cannot load any components in the zone
- UI shows "infinite page loading" that ends in timeout

### Behavior on Fresh Installation

When testing on a new CloudStack 4.22.1.0 instance with LDAP user import, logs show an error — **malformed LDAP filter syntax** (extra opening parenthesis `(` at the end):

```log
{"attributes":["uid","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(
```

### Comparison with Working Version (Root Admin)

On the version where Root Admin works correctly, the filter looks correct:

```log
{"attributes":["cn","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(cn=*))","level":"info","requestId":"c411e2c7-0468-46af-9120-b7d1fc652f36","scope":"Whole Subtree","timestamp":"2026-08-26T11:13:44Z","took-ms":15}
```

### versions

## Environment

| Parameter | Value |
|-----------|-------|
| **Product** | Apache CloudStack |
| **Version (before upgrade)** | 4.21.0.0 |
| **Version (after upgrade)** | 4.22.1.0 |
| **Hypervision** | KVM|

### The steps to reproduce the bug

## Steps to Reproduce

### Scenario 1: Upgrade from 4.21.0.0 → 4.22.1.0

1. Install CloudStack 4.21.0.0 with LDAP authentication configured
2. Upgrade to version 4.22.1.0
3. Attempt to login as a user **without** Root Admin role
4. **Observed result:**
- Login appears successful
- UI does not load components (infinite loading → timeout)

### Scenario 2: Fresh Installation 4.22.1.0

1. Deploy new CloudStack 4.22.1.0 instance
2. Configure LDAP authentication (goauthentik or similar server)
3. Import users from LDAP
4. Check CloudStack Management Server logs
5. **Observed result:**
- LDAP query with malformed filter (extra `(` at the end)

```log
{"attributes":["uid","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(
```

### Comparison with Working Version (Root Admin)

On the version where Root Admin works correctly, the filter looks correct:

```log
{"attributes":["cn","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(cn=*))","level":"info","requestId":"c411e2c7-0468-46af-9120-b7d1fc652f36","scope":"Whole Subtree","timestamp":"2026-08-26T11:13:44Z","took-ms":15}
```

### What to do about it?

## Expected Behavior

- LDAP filter should be syntactically correct
- Users of all roles (not only Root Admin) should successfully authenticate and access the UI
- Filter should match the format: `(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*))`

## Actual Behavior

- LDAP filter contains syntax error: `(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(`
- Non-Root Admin users cannot work in UI after authentication
- On fresh installation, LDAP user import fails due to invalid filter

## Questions

1. How to fix permissions in the "upgraded" CloudStack version where only Root Admin can authenticate without issues?
2. How to fix the issue in fresh installation with the LDAP query error (malformed filter syntax)?

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

まず、CloudStack 4.22.1.0 で LDAP ユーザーのインポートと非 Root Admin ユーザーのログインを再現し、次に management server のログと issue に示されている LDAP 検索リクエストを確認します。生成された LDAP フィルターが構文的に有効で、LDAP インポートが成功し、Root Admin ロールを持たないユーザーが UI を読み込めれば完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
java
領域
authentication, backend
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
活発
明瞭さ
おおむね明確
初心者へのやさしさ
45/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。