Skip to content

make sure pre saml login is enabled after saml is disabled - #13953

Open
DaanHoogland wants to merge 2 commits into
mainfrom
ghi12595-saml-disable-ldap-fallback
Open

make sure pre saml login is enabled after saml is disabled#13953
DaanHoogland wants to merge 2 commits into
mainfrom
ghi12595-saml-disable-ldap-fallback

Conversation

@DaanHoogland

@DaanHoogland DaanHoogland commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

Description

This PR...

Fixes: #12595

  • On enabling SAML, the user's current Source is now saved (via the generic user_details key/value store, UserDetailsDao — the same mechanism UserPasswordResetManagerImpl and the OAuth2 login command already use) before it gets overwritten to SAML2. Skipped if already SAML2/SAML2DISABLED (nothing meaningful to remember), and guarded against a null source (an edge case I found via the pre-existing test).
  • On disabling SAML with enable.login.with.disabled.saml=true, it now restores that saved source (e.g. LDAP) via a new getPreSamlSource helper, instead of hardcoding UNKNOWN. Falls back to UNKNOWN if nothing was ever recorded (pre-existing users from before this fix) or the stored value is unrecognized.

Types of changes

  • Breaking change (fix or feature that would cause existing functionality to change)
  • New feature (non-breaking change which adds functionality)
  • Bug fix (non-breaking change which fixes an issue)
  • Enhancement (improves an existing feature and functionality)
  • Cleanup (Code refactoring and cleanup, that may add test cases)
  • Build/CI
  • Test (unit or integration test code)

Feature/Enhancement Scale or Bug Severity

Feature/Enhancement Scale

  • Major
  • Minor

Bug Severity

  • BLOCKER
  • Critical
  • Major
  • Minor
  • Trivial

Screenshots (if appropriate):

How Has This Been Tested?

How did you try to break this feature and the system with this change?

@codecov

codecov Bot commented Aug 22, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 61.29032% with 12 lines in your changes missing coverage. Please review.
✅ Project coverage is 19.73%. Comparing base (5e5ae0c) to head (08f943d).
⚠️ Report is 2 commits behind head on main.

Files with missing lines Patch % Lines
...g/apache/cloudstack/saml/SAML2AuthManagerImpl.java 61.29% 10 Missing and 2 partials ⚠️
Additional details and impacted files
@@             Coverage Diff              @@
##               main   #13953      +/-   ##
============================================
+ Coverage     19.72%   19.73%   +0.01%     
- Complexity    19941    19961      +20     
============================================
  Files          6371     6371              
  Lines        575738   575802      +64     
  Branches      70471    70479       +8     
============================================
+ Hits         113582   113656      +74     
+ Misses       449810   449792      -18     
- Partials      12346    12354       +8     
Flag Coverage Δ
uitests 3.41% <ø> (ø)
unittests 21.01% <61.29%> (+0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions

github-actions Bot commented Aug 22, 2026

Copy link
Copy Markdown

🔴 Test Coverage Grade: D — Marginal

Metric Value
Line coverage 24.61%
Branch coverage 18.82%

Grade Scale

Grade Line Coverage Meaning
🟢 A ≥ 80% Excellent - this code sleeps well at night 😴
🟡 B 60-79% Good - almost there, don't stop now 😉
🟠 C 40-59% Acceptable - your code is wearing a seatbelt, but no airbags 😬
🔴 D 20-39% Marginal - boldly shipping where no test has gone before 🖖
⛔ F < 20% Failing - tests? what tests? 🔥

Branch coverage is shown as a secondary signal. Grade is determined by line coverage.
View full Actions run

@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

Ldap imported accounts which are saml enabled doesn't fallback to ldap if saml is disabled

2 participants