Skip to content

fix(auth): master does not compile — a merge put the old SAML ACS body back without its imports #886

Description

@alex-dembele

Problem

The backend on master (14f26e8e) does not compile, so no server can be built or deployed from it, and master CI is red (CI Status: failure, the backend binary build is skipped).

cd backend && go build ./cmd/server/
internal/handler/saml2_handler.go:41:18: undefined: base64
internal/handler/saml2_handler.go:49:15: undefined: SAMLResponse
internal/handler/saml2_handler.go:50:12: undefined: xml
… (too many errors)

Cause

Do not fix this by adding the imports back

The reintroduced body reads the email out of any posted XML, with no signature, issuer, audience or validity check, and opens a session for that account. That is the authentication bypass #866 closed. Adding the missing imports would compile it back into production.

Acceptance criteria

  1. backend/internal/handler/saml2_handler.go matches security(auth): SAML endpoints refuse every request until assertions are verified #866's intent: SAML2ACS and SAML2InitiateLogin refuse every request through oauthFailure(..., "provider_not_configured", "saml2", ...), and none of the hand-rolled parsing or provisioning code remains.
  2. go build ./... && go vet ./... pass on the branch.
  3. go test ./... -race passes, including security(auth): SAML endpoints refuse every request until assertions are verified #866's own tests proving the ACS creates no user and no session.
  4. Nothing else from e86df5cd is lost: the SSO sign-in success returns tokens as JSON instead of session cookies and a redirect #803 changes outside SAML stay as they are.

Definition of Done

  • Command output pasted here.
  • Progress comment in the CLAUDE.md format; PR with Closes this issue.

Activity

  1. added this to the trust-v1 milestone on Oct 2, 2026
  2. added
    area:securityCybersecurity and threat intelligence
    priority:P0Blocking: nothing else ships until this closes
    type:securitySecurity defect or hardening
    priority:P0-criticalProduction broken or exposed — work now
    status:readyMeets the ready definition
    tier:0-trustTrust: security, isolation, evidence integrity
    and removed
    status:readyMeets the ready definition
    on Oct 2, 2026
  3. alex-dembele commented on Oct 2, 2026

    @alex-dembele
    MemberAuthor

    claude — 2026-10-02

    Done — nothing on this issue: it duplicates #881, opened earlier for the same break. PR #882 already restores saml2_handler.go exactly as #866 left it (069b3db8). Full backend gate green: 80 packages ok, 0 FAIL, including TestSAML2ACS_RefusesAWellFormedSuccessResponse.
    Next — the owner decides between #882 and this issue's branch (fix/886-saml-handler-build) and closes the duplicate. Don't fix it by adding the missing imports: that would put the unsigned-assertion ACS back into service.
    Blocked on — @owner decision (pick a PR)

  4. alex-dembele commented on Oct 2, 2026

    @alex-dembele
    MemberAuthor

    backend — 2026-10-02

    Done

    Verified

    • go build ./... ok.
    • go vet ./... && go test ./... -race: exit 0, 80 packages ok, 0 FAIL. That includes TestSAML2ACS_RefusesAWellFormedSuccessResponse and TestSAML2ACS_RefusesAnEmptyPost.

    Criteria: 1 ✅ · 2 ✅ · 3 ✅ · 4 ✅ (only this file differs from master)

    Next: owner review and merge of #888. Master stays unbuildable until then.

    Blocked on: nothing.

  5. added a commit that references this issue on Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:backendGo, /internal, /pkgarea:securityCybersecurity and threat intelligencepriority:P0Blocking: nothing else ships until this closespriority:P0-criticalProduction broken or exposed — work nowstatus:in-reviewPR opentier:0-trustTrust: security, isolation, evidence integritytype:securitySecurity defect or hardening

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions