Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Session key is not cleared when SAML Global Log Out API is called

Open
#13,997 2 comments 0 reactions 0 assignees View on GitHub

A pull request for this has already been merged.

  • #14017 by @DaanHoogland — merged

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
20/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
java

Research direction

Start by reviewing the linked merged pull request #14017, then reproduce the samlSlo API flow described in the issue and inspect the redirect response in the browser Network tab. Done means the logout response clears the listed session cookies and a subsequent login works without clearing browser data.

Written by the indexing model from the issue text.

Description

bug component:saml
problem

Within the portal, SAML accounts operate normally without any issues until the logout process. Currently, a loop is generated during sign-out, and the web browser session is never properly terminated. As a result, users must either clear their browser cache or open a new session in incognito/private mode to log in again.

versions

ACS. 4.22.x

The steps to reproduce the bug
  1. Enable Saml integration with Cloudstack

  2. Login as saml user

Check the session key

Image
  1. Execute the following api

https://cloudstack.apache.org/api/apidocs-4.22/apis/samlSlo.html

https://your-mgmt-serverip:8080/client/api?command=samlSlo,

  • If your IdP exposes its own Single Logout trigger, use that (it should redirect the browser to CloudStack's samlSlo URL).

Inspect the response in the Network tab

  • Find the command=samlSlo request.
  • Check its response headers: status 302, a Location header pointing at the redirect target — but no Set-Cookie header clearing JSESSIONID/userid/sessionkey (i.e. no Max-Age=0 entries for those names).
HTTP/1.1 302 Found
Content-Type: text/xml;charset=utf-8
Location: http://10.0.32.243:8080/simplesaml/saml2/idp/SingleLogoutService.php?SAMLRequest=nZGxasMwEIb3PoXRHluWVVsWsUMhFAJphybt0KUo8iUWsSXVkk0fv0rSQOjQocvBwd333S%2FNF199F00wOGV0hdIYowi0NI3Shwq9bh9nDC3qu7kTfUcsX5uDGf0LfI7gfLQMRWnhz6ut95YnSYpjHGckJjTjDDOcONXbDk77yRmSqMYmm4Dv4ELbwDApCbFtLYpWywp1%2BGgYxdBK24wEpqLtC%2BOnI3UuzzRWYcq5EVbaeaF9hQgm%2BQyzGWFbnHNacBxuyPN3FL1dc5FTrpBUO35JUqFx0NwIpxzXogfHveSbh6c1D6PcDsYbaTpUX4Lzs3C4JfwNEM7BcHoXVJvhEAsrZAux7MzYhKPlkRIyT27RV9FzQK2W%2FxJ9lHtW3BMpMaVUZGW5k2XTUCZ3ZZFmZJ9LSKnEaUrx1X2x1T%2Ftr%2B%2BtvwE%3D
Content-Length: 0
Image Image
  1. Login again
Image
  1. Logout saml user from the ui

Check the session key is not cleared

Image
What to do about it?

Session key should be cleared

Dominant language
Java
Stars
3.1k
Forks
1.4k
Avg merge
6d 20h
Merged PRs (30d)
27

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/cloudstack

All issues in apache/cloudstack

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.