Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

LDAP Authentication: Malformed LDAP Filter Syntax, Authorization Works Only for Root Admin

Abierto
#13,983 2 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
45/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
java

Línea de trabajo

Comienza reproduciendo la importación de usuarios LDAP y un inicio de sesión de un usuario que no sea Root Admin en CloudStack 4.22.1.0; después, inspecciona los logs del servidor de gestión y la solicitud de búsqueda LDAP mostrada en el issue. Se considera completado cuando el filtro LDAP generado sea sintácticamente válido, la importación LDAP se realice correctamente y los usuarios sin el rol Root Admin puedan cargar la UI.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

component:LDAP
problem

Issue Description

After upgrading CloudStack from version 4.21.0.0 to 4.22.1.0, LDAP user authentication stopped working for all roles except Root Admin.

Symptoms
  1. Root Admin — authentication succeeds, UI works correctly
  2. Non-Root Admin users — authentication appears to succeed, but after login:
    • System cannot load any components in the zone
    • UI shows "infinite page loading" that ends in timeout
Behavior on Fresh Installation

When testing on a new CloudStack 4.22.1.0 instance with LDAP user import, logs show an error — malformed LDAP filter syntax (extra opening parenthesis ( at the end):

{"attributes":["uid","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(
Comparison with Working Version (Root Admin)

On the version where Root Admin works correctly, the filter looks correct:

{"attributes":["cn","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(cn=*))","level":"info","requestId":"c411e2c7-0468-46af-9120-b7d1fc652f36","scope":"Whole Subtree","timestamp":"2026-08-26T11:13:44Z","took-ms":15}
versions

Environment

Parameter Value
Product Apache CloudStack
Version (before upgrade) 4.21.0.0
Version (after upgrade) 4.22.1.0
Hypervision KVM
The steps to reproduce the bug

Steps to Reproduce

Scenario 1: Upgrade from 4.21.0.0 → 4.22.1.0
  1. Install CloudStack 4.21.0.0 with LDAP authentication configured
  2. Upgrade to version 4.22.1.0
  3. Attempt to login as a user without Root Admin role
  4. Observed result:
    • Login appears successful
    • UI does not load components (infinite loading → timeout)
Scenario 2: Fresh Installation 4.22.1.0
  1. Deploy new CloudStack 4.22.1.0 instance
  2. Configure LDAP authentication (goauthentik or similar server)
  3. Import users from LDAP
  4. Check CloudStack Management Server logs
  5. Observed result:
    • LDAP query with malformed filter (extra ( at the end)
{"attributes":["uid","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(
Comparison with Working Version (Root Admin)

On the version where Root Admin works correctly, the filter looks correct:

{"attributes":["cn","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(cn=*))","level":"info","requestId":"c411e2c7-0468-46af-9120-b7d1fc652f36","scope":"Whole Subtree","timestamp":"2026-08-26T11:13:44Z","took-ms":15}
What to do about it?

Expected Behavior

  • LDAP filter should be syntactically correct
  • Users of all roles (not only Root Admin) should successfully authenticate and access the UI
  • Filter should match the format: (&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*))

Actual Behavior

  • LDAP filter contains syntax error: (&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(
  • Non-Root Admin users cannot work in UI after authentication
  • On fresh installation, LDAP user import fails due to invalid filter

Questions

  1. How to fix permissions in the "upgraded" CloudStack version where only Root Admin can authenticate without issues?
  2. How to fix the issue in fresh installation with the LDAP query error (malformed filter syntax)?
Lenguaje dominante
Java
Estrellas
3.1k
Forks
1.4k
Merge medio
6 d 20 h
PR fusionados (30 d)
27

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de apache/cloudstack

Todos los issues de apache/cloudstack

Issues similares

Más issues de Java

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.