Keycloak oauth configuration code not cleared
@Damans227 ci sta già lavorando.
Dal 12/8/2026.
Valutazione
Questa issue non è ancora stata valutata.
Descrizione
problem
No response
versions
ACS 4.23 RC
The keycloak oauth was introduced with the pr
https://github.com/apache/cloudstack/pull/13033
The steps to reproduce the bug
Steps to reproduce the behaviour
- Run a keycloack service using a docker container
docker run -d --name keycloak -p 8081:8080 \
-e KEYCLOAK_ADMIN=admin -e KEYCLOAK_ADMIN_PASSWORD=admin \
quay.io/keycloak/keycloak:latest start-dev
- Login to the keycloak ui and create client
Example : create a client name cloudstack
- Valid redirect URIs: http://mgmtip:8080/*
- Web origins: http://mgmtip:8080
- In CloudStack (Settings → OAuth Settings, registering the keycloak provider
- Redirect URI: http://mgmtip:8080/client/#/verifyOauth (must match the Keycloak client's registered value exactly)
- Authorize URL: http://keycloakip:8081/realms//protocol/openid-connect/auth
- Token URL: http://keycloakip:8081/realms//protocol/openid-connect/token
-
Create a matching CloudStack user (username == the Keycloak test user's email).
-
Try login with keycloak provider flow end to end > Login works fine
Issue to reproduce the bug
- Cause one failure attempt with keycloak oauth attempt
Rename a CloudStack username so it no longer matches an OAuth-configured account (or use an IdP account with no matching CloudStack user).
-
Log in via the IdP with valid credentials: the code exchange succeeds (verifyOAuthCodeAndGetUser returns the correct email), but oauthlogin fails downstream because OAuth2UserAuthenticator.authenticate() can't find a matching account (userAccountDao.getUserAccount() returns null) — note this returns false before verifyUser() is ever called, so the cached token is never cleared.
-
Do not restart the management server.
-
Fix the mismatch, then perform a genuinely fresh IdP login (new authorization code) and retry.
-
Issue gets resolved if the management server is restarted
Logs
root@Cloudstack-422-before:/home/ubuntu# cat /var/log/cloudstack/management/management-server.log |grep -i "logid:84fb4f98"
2026-08-12 08:05:42,795 DEBUG [c.c.a.ApiServlet] (qtp659590237-697:[ctx-95f375f8]) (logid:84fb4f98) ===START=== 192.168.55.207 -- GET provider=keycloak&secretcode=031a66aa-7525-b93e-3757-73350343db82.XbFFhkc0E7t7nZJ_7joLuMwU.5ed14f93-3977-4527-9649-c88da3e7be55&domain=d1&command=verifyOAuthCodeAndGetUser&response=json
2026-08-12 08:05:42,796 DEBUG [c.c.a.ApiServlet] (qtp659590237-697:[ctx-95f375f8]) (logid:84fb4f98) Authentication failure: Unable to verify the code provided
2026-08-12 08:05:42,796 DEBUG [c.c.a.ApiServlet] (qtp659590237-697:[ctx-95f375f8]) (logid:84fb4f98) ===END=== 192.168.55.207 -- GET provider=keycloak&secretcode=031a66aa-7525-b93e-3757-73350343db82.XbFFhkc0E7t7nZJ_7joLuMwU.5ed14f93-3977-4527-9649-c88da3e7be55&domain=d1&command=verifyOAuthCodeAndGetUser&response=json
root@Cloudstack-422-before:/home/ubuntu# cat /var/log/cloudstack/management/management-server.log |grep -i "logid:2a077ac1"
2026-08-12 08:06:03,408 DEBUG [c.c.a.ApiServlet] (qtp659590237-694:[ctx-9bb94840]) (logid:2a077ac1) ===START=== 192.168.55.207 -- GET provider=keycloak&secretcode=a51ebc47-eac5-a5b2-ccc5-c38f10a6a3c1.XbFFhkc0E7t7nZJ_7joLuMwU.5ed14f93-3977-4527-9649-c88da3e7be55&domain=d1&command=verifyOAuthCodeAndGetUser&response=json
2026-08-12 08:06:03,409 DEBUG [c.c.a.ApiServlet] (qtp659590237-694:[ctx-9bb94840]) (logid:2a077ac1) Authentication failure: Unable to verify the code provided
2026-08-12 08:06:03,409 DEBUG [c.c.a.ApiServlet] (qtp659590237-694:[ctx-9bb94840]) (logid:2a077ac1) ===END=== 192.168.55.207 -- GET provider=keycloak&secretcode=a51ebc47-eac5-a5b2-ccc5-c38f10a6a3c1.XbFFhkc0E7t7nZJ_7joLuMwU.5ed14f93-3977-4527-9649-c88da3e7be55&domain=d1&command=verifyOAuthCodeAndGetUser&response=json
What to do about it?
Expected: The new code is validated against the IdP's token endpoint independently.
Actual: The plugin never makes a second token-exchange call — it serves the result off the token cached in st
- Lingua principale
- Java
- Stelle
- 3.1k
- Fork
- 1.4k
- Merge medio
- 6g 20h
- PR unite (30g)
- 27
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di apache/cloudstack
-
bug
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
apache/cloudstack#14222 ·
-
create-kubernetes-binaries-iso.sh builds the ISO without setting a volume ID on EL8 based os's Apertabug component:kubernetes
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
apache/cloudstack#14180 ·
-
bug component:projects component:UI
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
apache/cloudstack#14070 · 5 commenti ·
-
component:backup
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
apache/cloudstack#14013 ·
-
KVM agent fails to connect to Ceph RBD storage pool after upgrading Ceph client to Tentacle 20.2.4 Apertabug component:ceph
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
apache/cloudstack#13989 · 3 commenti ·
Tutte le issue di apache/cloudstack
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
elastic/gradle-plugins#157 ·
-
enhancement Tools
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 75/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
apache/rocketmq-dashboard#5008 ·
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
DETECT_PARAMETER_NAMES=false silently disables @ConstructorProperties-based Creator detection too Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
FasterXML/jackson-databind#6229 ·