Session key is not cleared when SAML Global Log Out API is called
- 主要语言
- Java
- 星标
- 3.1k
- 派生
- 1.4k
- 平均合并
- 6 天 19 小时
- 30 天内合并 PR
- 32
描述
### problem
Within the portal, SAML accounts operate normally without any issues until the logout process. Currently, a loop is generated during sign-out, and the web browser session is never properly terminated. As a result, users must either clear their browser cache or open a new session in incognito/private mode to log in again.
### versions
ACS. 4.22.x
### The steps to reproduce the bug
1. Enable Saml integration with Cloudstack
2. Login as saml user
Check the session key
2. Execute the following api
https://cloudstack.apache.org/api/apidocs-4.22/apis/samlSlo.html
https://your-mgmt-serverip:8080/client/api?command=samlSlo,
- If your IdP exposes its own Single Logout trigger, use that (it should redirect the browser to CloudStack's samlSlo URL).
Inspect the response in the Network tab
- Find the command=samlSlo request.
- Check its response headers: status 302, a Location header pointing at the redirect target — but no Set-Cookie header clearing JSESSIONID/userid/sessionkey (i.e. no Max-Age=0 entries for those names).
```
HTTP/1.1 302 Found
Content-Type: text/xml;charset=utf-8
Location: http://10.0.32.243:8080/simplesaml/saml2/idp/SingleLogoutService.php?SAMLRequest=nZGxasMwEIb3PoXRHluWVVsWsUMhFAJphybt0KUo8iUWsSXVkk0fv0rSQOjQocvBwd333S%2FNF199F00wOGV0hdIYowi0NI3Shwq9bh9nDC3qu7kTfUcsX5uDGf0LfI7gfLQMRWnhz6ut95YnSYpjHGckJjTjDDOcONXbDk77yRmSqMYmm4Dv4ELbwDApCbFtLYpWywp1%2BGgYxdBK24wEpqLtC%2BOnI3UuzzRWYcq5EVbaeaF9hQgm%2BQyzGWFbnHNacBxuyPN3FL1dc5FTrpBUO35JUqFx0NwIpxzXogfHveSbh6c1D6PcDsYbaTpUX4Lzs3C4JfwNEM7BcHoXVJvhEAsrZAux7MzYhKPlkRIyT27RV9FzQK2W%2FxJ9lHtW3BMpMaVUZGW5k2XTUCZ3ZZFmZJ9LSKnEaUrx1X2x1T%2Ftr%2B%2BtvwE%3D
Content-Length: 0
```
4. Login again
4. Logout saml user from the ui
Check the session key is not cleared
### What to do about it?
Session key should be cleared
贡献指南
调研方向
首先查看链接的已合并 pull request #14017,然后复现 issue 中描述的 samlSlo API 流程,并在浏览器的 Network 标签页中检查重定向响应。当 logout 响应清除列出的会话 Cookie,且后续登录无需清除浏览器数据即可成功时,即表示完成。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- java
- 领域
- api, authentication, backend
- Issue 类型
- 缺陷
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 20/100