`sf org open` opens wrong user
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Bug
- Clarity
- Needs clarification
- Activity status
- Stale
- Tech stack
- node.js
- Domain
- authentication, cli
Research direction
Start with the sf org open command and its --browser path, then inspect the authentication behavior described for multiple scratch-org users. Done means repeated opens for usr1, usr2, and usr3 consistently establish the requested user's session rather than reusing the admin or first browser user.
Written by the indexing model from the issue text.
Description
Summary
I created a few test users (usr1, usr2, usr3) on scratch org using sf org create user like this:
sf org user create -o tst -f .\config\user\def_adviser.json -a usr1
Successfully created user "[email protected]" with ID 005Ad00000FIZzaIAH for org 00DAd000008CqMPMA0.
See more details about this user by running "sf org user display -o [email protected]".
sf org user create -o tst -f .\config\user\def_adviser.json -a usr2
Successfully created user "[email protected]" with ID 005Ad00000FIaE5IAL for org 00DAd000008CqMPMA0.
See more details about this user by running "sf org user display -o [email protected]".
sf org user create -o tst -f .\config\user\def_adviser.json -a usr3
Successfully created user "[email protected]" with ID 005Ad00000FIaHJIA1 for org 00DAd000008CqMPMA0.
See more details about this user by running "sf org user display -o [email protected]".
and then I tried to login as those users using sf org open -o usr1 or usr2 or usr3.
Expected result
I should login as the specified user.
Actual result
It will ask me for password reset for specified user once, BUT log me in as scratch admin user. Even if I logged out of "User User" (the main user), sf org open would still open the main user and not the one I specify.
However, if I specified different browser using sf org open -o usr1 --browser edge, it will log me in as specified user BUT only for the first time.
Following attempt with different user will still open the first user:
sf org open -o usr3 --browser edge
If I logout from that user on Edge and try to login as usr3, it will still log me in as usr1.
If it's my first login as usr3, it will prompt me to change password for usr3 and still login as usr1, a user from which I logged out and which shouldn't have active session.
What's even more interesting is that usr3 will have this login in Login History, but usr1 does not, even though it logged me as usr1 and I act as usr1. This may hint some security issue present in Salesforce.
Additional information
- This is user definition file:
{
"FirstName": "Adviser",
"LastName": "Test1",
"TimeZoneSidKey": "Europe/London",
"LocaleSidKey": "en_US",
"EmailEncodingKey": "UTF-8",
"LanguageLocaleKey": "en_US",
"profileName": "Standard User"
}
-
Scratch Org was created using Org Shape, so I have more user licenses available than empty scratch org.
-
This started affecting our automated tests, which used to open specific test user and now open admin user instead.
System Information
CLI:
@salesforce/cli/2.102.6 win32-x64 node-v23.3.0
Plugin Version:
@oclif/plugin-autocomplete 3.2.34 (core)
@oclif/plugin-commands 4.1.32 (core)
@oclif/plugin-help 6.2.32 (core)
@oclif/plugin-not-found 3.2.64 (core)
@oclif/plugin-plugins 5.4.46 (core)
@oclif/plugin-search 1.2.28 (core)
@oclif/plugin-update 4.7.3 (core)
@oclif/plugin-version 2.2.32 (core)
@oclif/plugin-warn-if-update-available 3.1.46 (core)
@oclif/plugin-which 3.2.39 (core)
@salesforce/cli 2.102.6 (core)
agent 1.24.2 (core)
apex 3.6.19 (core)
api 1.3.3 (core)
auth 3.7.18 (core)
code-analyzer 5.0.0 (user)
community 3.3.8 (user)
custom-metadata 3.3.33 (user)
data 4.0.51 (core)
deploy-retrieve 3.22.38 (core)
dev 2.1.12 (user)
info 3.4.80 (core)
lightning-dev 2.10.2 (user)
limits 3.3.64 (core)
marketplace 1.3.8 (core)
org 5.9.22 (core)
packaging 1.22.1 (user)
schema 3.3.78 (core)
settings 2.4.42 (core)
sobject 1.4.68 (core)
telemetry 3.6.53 (core)
templates 56.3.60 (core)
trust 3.7.113 (core)
user 3.6.34 (core)
@salesforce/sfdx-scanner 4.7.0 (user)
sfdmu 4.33.17 (user)
sfdx-hardis 4.52.0 (user)
SF ENV. VARS.
SF_AUTOUPDATE_DISABLE,true
SF_DISABLE_AUTOUPDATE,true
SF_UPDATE_INSTRUCTIONS,Use "npm update --global @salesforce/cli" to update npm-based installations.
SF_BETA_TRACK_FILE_MOVES,true
Windows: true
Shell: powershell
Channel: stable
Diagnostics
✅ pass - salesforcedx plugin isn’t installed
✅ pass - you don't have any linked plugins
✅ pass - [@salesforce/plugin-trust] can ping: https://registry.npmjs.org
✅ pass - [@salesforce/plugin-trust] can ping: https://registry.yarnpkg.com
✅ pass - [@salesforce/plugin-trust] can ping: https://registry.npmjs.org/
✅ pass - using latest or latest-rc CLI version
✅ pass - can access: https://test.salesforce.com
✅ pass - can access: https://appexchange.salesforce.com/services/data
✅ pass - can access: https://developer.salesforce.com/media/salesforce-cli/sf/channels/stable/sf-win32-x64-buildmanifest
❌ fail - [@salesforce/plugin-auth] CLI supports v2 crypto
✅ pass - [@salesforce/plugin-auth] CLI using stable v1 crypto
✅ pass - [@salesforce/plugin-deploy-retrieve] sourceApiVersion matches apiVersion
- Dominant language
- No language data
- Stars
- 571
- Forks
- 80
- Avg merge
- 2d 21h
- Merged PRs (30d)
- 3
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from forcedotcom/cli
-
investigating validated
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
forcedotcom/cli#3657 · 2 comments ·
-
area:afdx owned by another team
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
forcedotcom/cli#3645 · 2 comments ·
-
bug investigating validated
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
forcedotcom/cli#3644 · 6 comments ·
-
area:afdx bug investigating owned by another team validated
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
forcedotcom/cli#3625 · 4 comments ·
-
area:afdx bug owned by another team
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
forcedotcom/cli#3608 · 2 comments ·
Similar issues
-
security
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
comp/tools duplicate P2 sweeper:risk-compatibility tool/mcp type/bug
Difficulty 1/5 Under an hour Newbie friendliness 88/100
NousResearch/hermes-agent#132042 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
EverMind-AI/Raven#842 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
BasedHardware/omi#20401 · 1 comment ·
Maintainers usually reply within 1 day