nextcloud / nextcloud/server

[Bug]: Theming is not applied on SSO user disabled error page

Open
#44,777 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

0. Needs triage 27-feedback bug feature: authentication feature: theming
Dominant language
PHP
Stars
36.9k
Forks
5.2k
Avg merge
2d 3h
Merged PRs (30d)
713

Description

⚠️ This issue respects the following points: ⚠️
Bug description

In NC27 with activated theming app and custom logo and backgroud I am getting the default theming if a saml user is deactivated and tries to login.

Steps to reproduce
  1. Have SAML enabled and configured
  2. Have the user already known in Nextcloud
  3. Disable the user in Nextcloud
  4. Login as this user per SAML
  5. bam!

Analysis:

In base.php handleLogin() is called, and inside there OC_User::handleApacheAuth() is called. Which again calls its own method loginWithApache(). There we have a check whether the user is enabled: if ($userSession->getUser() && !$userSession->getUser()->isEnabled()) {

In our case they are not enable and so a LoginException is thrown with the translated message "User disabled".

This then is only caught in index.php where it prints the error page. OC_Template::printErrorPage() is utilized. It actually would load theming, if it is not already, provided it is enabled for the user! But without a user – login refused - this check returns false and so we have not theming in that case.

Expected behavior

Theming applies

Installation method

None

Nextcloud Server version

27

Operating system

None

PHP engine version

None

Web server

None

Database engine version

None

Is this bug present after an update or on a fresh install?

None

Are you using the Nextcloud Server Encryption module?

None

What user-backends are you using?
  • Default user-backend (database)
  • LDAP/ Active Directory
  • SSO - SAML
  • Other
Configuration report

No response

List of activated Apps

No response

Nextcloud Signing status

No response

Nextcloud Logs

No response

Additional info

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with base.php and follow handleLogin() through OC_User::handleApacheAuth() and loginWithApache(), then inspect the exception handling in index.php and OC_Template::printErrorPage(). Reproduce the disabled SSO-user login case and verify that the configured theming is applied to the resulting User disabled error page.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
authentication, design
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.