apache / apache/cloudstack

After removing SAML auth, user should be able to login via password directly

Open
#6,672 5 comments 0 reactions 0 assignees View on GitHub
type:improvement
Dominant language
Java
Stars
3.1k
Forks
1.4k
Avg merge
6d 19h
Merged PRs (30d)
32

Description

##### ISSUE TYPE
* Bug Report

##### COMPONENT NAME
~~~
API via cmk
~~~

##### CLOUDSTACK VERSION
~~~
4.17.0.1
~~~

##### CONFIGURATION
N/A

##### OS / ENVIRONMENT
N/A

##### SUMMARY

##### STEPS TO REPRODUCE
~~~
step1: add user, add password for this user, play with this user.
step2: enable SAML SSO authentication for this user, either by webui or API
step3: When you choose to remove the SAML SSO authentication, via cmk : authorize samlsso enable=false userid=myuser id
step4: Try to login on webui with failure :)
~~~

##### EXPECTED RESULTS
User should be able to login on cloudstack web UI
When SSO is disable the field "source" on user table is SAML2DISABLED
When SSO has never been activated (and user is able to login via cloudstack directly) this field must be UNKNOWN.

##### ACTUAL RESULTS
User can't login on cloudstack web UI

Contributor guide

Open the contributing guide

Research direction

Start with the cmk `authorize samlsso enable=false userid=myuser` flow and trace how the user table's `source` value affects Web UI password login. Reproduce the transition from SAML2DISABLED, verify that login succeeds after disabling SSO, and confirm users who never used SSO retain source UNKNOWN.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
api, authentication
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.