Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

NullPointerException in ApiServlet.skip2FAcheckForUser for SAML SSO sessions when 2FA is not enabled

Offen
#13,815 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

@DaanHoogland arbeitet bereits daran.

Seit 13.8.2026.

  • #13871 von @DaanHoogland — offen

Bewertung

Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Anfängerfreundlichkeit
35/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Veraltet
Tech-Stack
java

Rechercherichtung

Beginne mit ApiServlet.java:512 und dem SAML-Anmeldepfad in SAML2LoginAPIAuthenticatorCmd und vergleiche dabei, wie der standardmäßige Benutzername/Passwort-Pfad IS_2FA_VERIFIED setzt. Stelle das Szenario mit einer alten SAML-Sitzung nach und überprüfe, dass die API eine gültige Antwort ohne NullPointerException zurückgibt und die UI nicht mehr leer gerendert wird.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

bug component:authentication
problem

ApiServlet.skip2FAcheckForUser(HttpSession) unboxes the IS_2FA_VERIFIED session attribute without a null check (ApiServlet.java:512):

boolean is2FAverified = (boolean) session.getAttribute(ApiConstants.IS_2FA_VERIFIED);

For sessions established via SAML SSO, this attribute is never set on the HttpSession. getAttribute returns null, unboxing to boolean throws a NullPointerException, and the API response write aborts with an empty 200 body. The UI then fails at permission.js (GenerateRoutes) and renders a blank page. This happens even though 2FA is not enabled anywhere in the environment.

Server-side error:

ERROR [c.c.a.ApiServlet] unknown exception writing api response
java.lang.NullPointerException: Cannot invoke "java.lang.Boolean.booleanValue()"
because the return value of "javax.servlet.http.HttpSession.getAttribute(String)" is null
at com.cloud.api.ApiServlet.skip2FAcheckForUser(ApiServlet.java:512)
at com.cloud.api.ApiServlet.processRequestInContext(ApiServlet.java:362)
at com.cloud.api.ApiServlet$1.run(ApiServlet.java:194)

versions

CloudStack: 4.22.1.0
Config: saml2.enabled=true; two-factor authentication NOT enabled (no enable.2fa configuration present)
IdP: Microsoft Entra ID (SAML 2.0)
OS: EL8.10
DB: MariaDB 10.5
Management server behind Apache httpd reverse proxy (443 -> 8443)

The steps to reproduce the bug
  1. Configure SAML SSO (saml2.enabled=true), with 2FA NOT enabled.
  2. Log in as a SAML user via SSO.
  3. Continue using the session until an API call reaches skip2FAcheckForUser (e.g. listUsers during UI bootstrap on a session that has aged).
  4. The API returns an empty 200 body; the UI renders a blank page.

Expected: SAML sessions without 2FA proceed normally and the API returns a valid response.
Actual: NullPointerException at ApiServlet.java:512, empty response, blank UI.

What to do about it?

Suggested fix:

  • Null-safe read at ApiServlet.java:512, e.g.:
    boolean is2FAverified = Boolean.TRUE.equals(session.getAttribute(ApiConstants.IS_2FA_VERIFIED));
  • Additionally, set IS_2FA_VERIFIED on the session in the SAML login path (SAML2LoginAPIAuthenticatorCmd) as the standard username/password login path does, so SAML sessions carry the attribute.

Workaround for operators:

  • Delete the JSESSIONID cookie and re-authenticate via SSO to establish a fresh session (confirmed working).
Vorherrschende Sprache
Java
Sterne
3.1k
Forks
1.4k
Ø Merge
6 T. 20 Std.
Gemergte PRs (30 T.)
27

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus apache/cloudstack

Alle Issues in apache/cloudstack

Ähnliche Issues

Weitere Issues zu Java

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.