apache / apache/cloudstack

After removing SAML auth, user should be able to login via password directly

未關閉
#6,672 5 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
type:improvement
主要語言
Java
星號
3.1k
分支
1.4k
平均合併
6 天 19 小時
30 天內合併 PR
32

描述

##### ISSUE TYPE
* Bug Report

##### COMPONENT NAME
~~~
API via cmk
~~~

##### CLOUDSTACK VERSION
~~~
4.17.0.1
~~~

##### CONFIGURATION
N/A

##### OS / ENVIRONMENT
N/A

##### SUMMARY

##### STEPS TO REPRODUCE
~~~
step1: add user, add password for this user, play with this user.
step2: enable SAML SSO authentication for this user, either by webui or API
step3: When you choose to remove the SAML SSO authentication, via cmk : authorize samlsso enable=false userid=myuser id
step4: Try to login on webui with failure :)
~~~

##### EXPECTED RESULTS
User should be able to login on cloudstack web UI
When SSO is disable the field "source" on user table is SAML2DISABLED
When SSO has never been activated (and user is able to login via cloudstack directly) this field must be UNKNOWN.

##### ACTUAL RESULTS
User can't login on cloudstack web UI

貢獻指南

開啟貢獻指南

研究方向

Start with the cmk `authorize samlsso enable=false userid=myuser` flow and trace how the user table's `source` value affects Web UI password login. Reproduce the transition from SAML2DISABLED, verify that login succeeds after disabling SSO, and confirm users who never used SSO retain source UNKNOWN.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
java
領域
api, authentication
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。