Repository navigation
fix(auth): master does not compile — a merge put the old SAML ACS body back without its imports #886
Copy link
Copy link
Closed
Labels
area:backendGo, /internal, /pkgGo, /internal, /pkgarea:securityCybersecurity and threat intelligenceCybersecurity and threat intelligencepriority:P0Blocking: nothing else ships until this closesBlocking: nothing else ships until this closespriority:P0-criticalProduction broken or exposed — work nowProduction broken or exposed — work nowstatus:in-reviewPR openPR opentier:0-trustTrust: security, isolation, evidence integrityTrust: security, isolation, evidence integritytype:securitySecurity defect or hardeningSecurity defect or hardening
Milestone
Description
Activity
- addedarea:securityCybersecurity and threat intelligenceCybersecurity and threat intelligencepriority:P0Blocking: nothing else ships until this closesBlocking: nothing else ships until this closestype:securitySecurity defect or hardeningSecurity defect or hardeningarea:backendGo, /internal, /pkgGo, /internal, /pkgpriority:P0-criticalProduction broken or exposed — work nowProduction broken or exposed — work nowstatus:readyMeets the ready definitionMeets the ready definitiontier:0-trustTrust: security, isolation, evidence integrityTrust: security, isolation, evidence integritystatus:in-progressAn agent is working itAn agent is working itand removedstatus:readyMeets the ready definitionMeets the ready definition
on Oct 2, 2026 claude — 2026-10-02
Done — nothing on this issue: it duplicates #881, opened earlier for the same break. PR #882 already restores
saml2_handler.goexactly as #866 left it (069b3db8). Full backend gate green: 80 packagesok, 0FAIL, includingTestSAML2ACS_RefusesAWellFormedSuccessResponse.
Next — the owner decides between #882 and this issue's branch (fix/886-saml-handler-build) and closes the duplicate. Don't fix it by adding the missing imports: that would put the unsigned-assertion ACS back into service.
Blocked on — @owner decision (pick a PR)- added a commit that references this issue
on Oct 2, 2026 - linked a pull request that will close this issuefix(auth): restore the fail-closed SAML handler so master compiles (#886) #888
on Oct 2, 2026 backend — 2026-10-02
Done
backend/internal/handler/saml2_handler.gorestored to security(auth): SAML endpoints refuse every request until assertions are verified #866's version (069b3db8): both SAML entry points refuse every request, and the hand-rolled ACS,provisionSAML2UserandapplyGroupRoleMappingare gone again.- No other file changes.
- PR fix(auth): restore the fail-closed SAML handler so master compiles (#886) #888.
Verified
go build ./...ok.go vet ./... && go test ./... -race: exit 0, 80 packages ok, 0 FAIL. That includesTestSAML2ACS_RefusesAWellFormedSuccessResponseandTestSAML2ACS_RefusesAnEmptyPost.
Criteria: 1 ✅ · 2 ✅ · 3 ✅ · 4 ✅ (only this file differs from master)
Next: owner review and merge of #888. Master stays unbuildable until then.
Blocked on: nothing.
- addedstatus:in-reviewPR openPR openand removedstatus:in-progressAn agent is working itAn agent is working it
on Oct 2, 2026 - added a commit that references this issue
on Oct 2, 2026
Metadata
Metadata
Assignees
Labels
area:backendGo, /internal, /pkgGo, /internal, /pkgarea:securityCybersecurity and threat intelligenceCybersecurity and threat intelligencepriority:P0Blocking: nothing else ships until this closesBlocking: nothing else ships until this closespriority:P0-criticalProduction broken or exposed — work nowProduction broken or exposed — work nowstatus:in-reviewPR openPR opentier:0-trustTrust: security, isolation, evidence integrityTrust: security, isolation, evidence integritytype:securitySecurity defect or hardeningSecurity defect or hardening
Problem
The backend on
master(14f26e8e) does not compile, so no server can be built or deployed from it, and master CI is red (CI Status: failure, the backend binary build is skipped).Cause
069b3db8(security(auth): SAML endpoints refuse every request until assertions are verified #866) turned SAML sign-in off.SAML2ACSandSAML2InitiateLoginbecame one-line refusals, the hand-rolled XML parsing and user provisioning were deleted, and the imports were trimmed to match.e86df5cd("Merge branch 'master' into security/866-saml-fail-closed") then brought back the old body ofSAML2ACSfrom SSO sign-in success returns tokens as JSON instead of session cookies and a redirect #803 (f0498d18), along withprovisionSAML2UserandapplyGroupRoleMapping. It kept security(auth): SAML endpoints refuse every request until assertions are verified #866's trimmed imports and security(auth): SAML endpoints refuse every request until assertions are verified #866's doc comment, which still says "SAML2ACS refuses every assertion".Do not fix this by adding the imports back
The reintroduced body reads the email out of any posted XML, with no signature, issuer, audience or validity check, and opens a session for that account. That is the authentication bypass #866 closed. Adding the missing imports would compile it back into production.
Acceptance criteria
backend/internal/handler/saml2_handler.gomatches security(auth): SAML endpoints refuse every request until assertions are verified #866's intent:SAML2ACSandSAML2InitiateLoginrefuse every request throughoauthFailure(..., "provider_not_configured", "saml2", ...), and none of the hand-rolled parsing or provisioning code remains.go build ./... && go vet ./...pass on the branch.go test ./... -racepasses, including security(auth): SAML endpoints refuse every request until assertions are verified #866's own tests proving the ACS creates no user and no session.e86df5cdis lost: the SSO sign-in success returns tokens as JSON instead of session cookies and a redirect #803 changes outside SAML stay as they are.Definition of Done
Closesthis issue.