apache / apache/cloudstack

Session key is not cleared when SAML Global Log Out API is called

オープン
#13,997 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
bug component:saml
主要言語
Java
スター
3.1k
フォーク
1.4k
平均マージ
6日 19時間
マージ済み PR(30日)
32

説明

### problem

Within the portal, SAML accounts operate normally without any issues until the logout process. Currently, a loop is generated during sign-out, and the web browser session is never properly terminated. As a result, users must either clear their browser cache or open a new session in incognito/private mode to log in again.

### versions

ACS. 4.22.x

### The steps to reproduce the bug

1. Enable Saml integration with Cloudstack

2. Login as saml user

Check the session key

Image

2. Execute the following api

https://cloudstack.apache.org/api/apidocs-4.22/apis/samlSlo.html

https://your-mgmt-serverip:8080/client/api?command=samlSlo,

- If your IdP exposes its own Single Logout trigger, use that (it should redirect the browser to CloudStack's samlSlo URL).

Inspect the response in the Network tab
- Find the command=samlSlo request.
- Check its response headers: status 302, a Location header pointing at the redirect target — but no Set-Cookie header clearing JSESSIONID/userid/sessionkey (i.e. no Max-Age=0 entries for those names).

```
HTTP/1.1 302 Found
Content-Type: text/xml;charset=utf-8
Location: http://10.0.32.243:8080/simplesaml/saml2/idp/SingleLogoutService.php?SAMLRequest=nZGxasMwEIb3PoXRHluWVVsWsUMhFAJphybt0KUo8iUWsSXVkk0fv0rSQOjQocvBwd333S%2FNF199F00wOGV0hdIYowi0NI3Shwq9bh9nDC3qu7kTfUcsX5uDGf0LfI7gfLQMRWnhz6ut95YnSYpjHGckJjTjDDOcONXbDk77yRmSqMYmm4Dv4ELbwDApCbFtLYpWywp1%2BGgYxdBK24wEpqLtC%2BOnI3UuzzRWYcq5EVbaeaF9hQgm%2BQyzGWFbnHNacBxuyPN3FL1dc5FTrpBUO35JUqFx0NwIpxzXogfHveSbh6c1D6PcDsYbaTpUX4Lzs3C4JfwNEM7BcHoXVJvhEAsrZAux7MzYhKPlkRIyT27RV9FzQK2W%2FxJ9lHtW3BMpMaVUZGW5k2XTUCZ3ZZFmZJ9LSKnEaUrx1X2x1T%2Ftr%2B%2BtvwE%3D
Content-Length: 0
```

Image

Image

4. Login again

Image

4. Logout saml user from the ui

Check the session key is not cleared

Image

### What to do about it?

Session key should be cleared

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

まず、リンクされているマージ済みの pull request #14017 を確認し、次に issue に記載されている samlSlo API フローを再現して、ブラウザーの Network タブでリダイレクトレスポンスを調査します。ログアウトレスポンスによって一覧にあるセッション Cookie が消去され、その後のログインがブラウザーデータを消去せずに成功すれば完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
java
領域
api, authentication, backend
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
20/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。