Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

LDAP Authentication: Malformed LDAP Filter Syntax, Authorization Works Only for Root Admin

Ouverte
#13,983 2 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Les mainteneurs répondent en général sous 1 jour

Personne n'a encore pris cette issue.

Évaluation

Difficulté
4/5
Temps estimé
3-5 jours
Accessibilité débutants
45/100
Type d'issue
Bug
Clarté
Plutôt claire
Activité
Active
Stack technique
java

Piste de recherche

Commencez par reproduire l’importation d’utilisateurs LDAP et la connexion d’un utilisateur qui n’est pas Root Admin sur CloudStack 4.22.1.0, puis examinez les journaux du serveur de gestion et la requête de recherche LDAP affichée dans l’issue. Le travail est considéré comme terminé lorsque le filtre LDAP généré est syntaxiquement valide, que l’importation LDAP réussit et que les utilisateurs ne disposant pas du rôle Root Admin peuvent charger l’UI.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

component:LDAP
problem

Issue Description

After upgrading CloudStack from version 4.21.0.0 to 4.22.1.0, LDAP user authentication stopped working for all roles except Root Admin.

Symptoms
  1. Root Admin — authentication succeeds, UI works correctly
  2. Non-Root Admin users — authentication appears to succeed, but after login:
    • System cannot load any components in the zone
    • UI shows "infinite page loading" that ends in timeout
Behavior on Fresh Installation

When testing on a new CloudStack 4.22.1.0 instance with LDAP user import, logs show an error — malformed LDAP filter syntax (extra opening parenthesis ( at the end):

{"attributes":["uid","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(
Comparison with Working Version (Root Admin)

On the version where Root Admin works correctly, the filter looks correct:

{"attributes":["cn","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(cn=*))","level":"info","requestId":"c411e2c7-0468-46af-9120-b7d1fc652f36","scope":"Whole Subtree","timestamp":"2026-08-26T11:13:44Z","took-ms":15}
versions

Environment

Parameter Value
Product Apache CloudStack
Version (before upgrade) 4.21.0.0
Version (after upgrade) 4.22.1.0
Hypervision KVM
The steps to reproduce the bug

Steps to Reproduce

Scenario 1: Upgrade from 4.21.0.0 → 4.22.1.0
  1. Install CloudStack 4.21.0.0 with LDAP authentication configured
  2. Upgrade to version 4.22.1.0
  3. Attempt to login as a user without Root Admin role
  4. Observed result:
    • Login appears successful
    • UI does not load components (infinite loading → timeout)
Scenario 2: Fresh Installation 4.22.1.0
  1. Deploy new CloudStack 4.22.1.0 instance
  2. Configure LDAP authentication (goauthentik or similar server)
  3. Import users from LDAP
  4. Check CloudStack Management Server logs
  5. Observed result:
    • LDAP query with malformed filter (extra ( at the end)
{"attributes":["uid","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(
Comparison with Working Version (Root Admin)

On the version where Root Admin works correctly, the filter looks correct:

{"attributes":["cn","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(cn=*))","level":"info","requestId":"c411e2c7-0468-46af-9120-b7d1fc652f36","scope":"Whole Subtree","timestamp":"2026-08-26T11:13:44Z","took-ms":15}
What to do about it?

Expected Behavior

  • LDAP filter should be syntactically correct
  • Users of all roles (not only Root Admin) should successfully authenticate and access the UI
  • Filter should match the format: (&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*))

Actual Behavior

  • LDAP filter contains syntax error: (&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(
  • Non-Root Admin users cannot work in UI after authentication
  • On fresh installation, LDAP user import fails due to invalid filter

Questions

  1. How to fix permissions in the "upgraded" CloudStack version where only Root Admin can authenticate without issues?
  2. How to fix the issue in fresh installation with the LDAP query error (malformed filter syntax)?
Langage dominant
Java
Étoiles
3.1k
Forks
1.4k
Merge moyen
5 j 19 h
PR mergées (30 j)
17

Préparer son environnement

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de apache/cloudstack

Toutes les issues de apache/cloudstack

Issues similaires

Plus d'issues Java

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.