Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

Session key is not cleared when SAML Global Log Out API is called

Offen
#13,997 2 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Ein zugehöriger Pull Request wurde bereits gemerged.

  • #14017 von @DaanHoogland — gemerged

Bewertung

Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Anfängerfreundlichkeit
20/100
Issue-Typ
Bug
Klarheit
Größtenteils klar
Aktivitätsstatus
Veraltet
Tech-Stack
java

Rechercherichtung

Beginne mit der Durchsicht des verlinkten gemergten Pull Requests #14017, reproduziere anschließend den in der Issue beschriebenen samlSlo API-Flow und untersuche die Redirect-Antwort im Browser-Tab Network. Die Aufgabe ist abgeschlossen, wenn die Logout-Antwort die aufgeführten Session-Cookies löscht und ein anschließender Login funktioniert, ohne Browserdaten zu löschen.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

bug component:saml
problem

Within the portal, SAML accounts operate normally without any issues until the logout process. Currently, a loop is generated during sign-out, and the web browser session is never properly terminated. As a result, users must either clear their browser cache or open a new session in incognito/private mode to log in again.

versions

ACS. 4.22.x

The steps to reproduce the bug
  1. Enable Saml integration with Cloudstack

  2. Login as saml user

Check the session key

Image
  1. Execute the following api

https://cloudstack.apache.org/api/apidocs-4.22/apis/samlSlo.html

https://your-mgmt-serverip:8080/client/api?command=samlSlo,

  • If your IdP exposes its own Single Logout trigger, use that (it should redirect the browser to CloudStack's samlSlo URL).

Inspect the response in the Network tab

  • Find the command=samlSlo request.
  • Check its response headers: status 302, a Location header pointing at the redirect target — but no Set-Cookie header clearing JSESSIONID/userid/sessionkey (i.e. no Max-Age=0 entries for those names).
HTTP/1.1 302 Found
Content-Type: text/xml;charset=utf-8
Location: http://10.0.32.243:8080/simplesaml/saml2/idp/SingleLogoutService.php?SAMLRequest=nZGxasMwEIb3PoXRHluWVVsWsUMhFAJphybt0KUo8iUWsSXVkk0fv0rSQOjQocvBwd333S%2FNF199F00wOGV0hdIYowi0NI3Shwq9bh9nDC3qu7kTfUcsX5uDGf0LfI7gfLQMRWnhz6ut95YnSYpjHGckJjTjDDOcONXbDk77yRmSqMYmm4Dv4ELbwDApCbFtLYpWywp1%2BGgYxdBK24wEpqLtC%2BOnI3UuzzRWYcq5EVbaeaF9hQgm%2BQyzGWFbnHNacBxuyPN3FL1dc5FTrpBUO35JUqFx0NwIpxzXogfHveSbh6c1D6PcDsYbaTpUX4Lzs3C4JfwNEM7BcHoXVJvhEAsrZAux7MzYhKPlkRIyT27RV9FzQK2W%2FxJ9lHtW3BMpMaVUZGW5k2XTUCZ3ZZFmZJ9LSKnEaUrx1X2x1T%2Ftr%2B%2BtvwE%3D
Content-Length: 0
Image Image
  1. Login again
Image
  1. Logout saml user from the ui

Check the session key is not cleared

Image
What to do about it?

Session key should be cleared

Vorherrschende Sprache
Java
Sterne
3.1k
Forks
1.4k
Ø Merge
6 T. 20 Std.
Gemergte PRs (30 T.)
27

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus apache/cloudstack

Alle Issues in apache/cloudstack

Ähnliche Issues

Weitere Issues zu Java

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.