kiranchavala opened a new issue, #13862:
URL: https://github.com/apache/cloudstack/issues/13862

   ### problem
   
   Is the global value of oauth2.plugins referenced or enforced anywhere in the 
code ?
   
   ### versions
   
   ACS 4.22
   ACS  4.23 rc 2 
   
   ### The steps to reproduce the bug
   
   oauth2.plugins (default "google,github", described as "List of OAuth 
plugins") is declared but is it used anywhere for validation ation. 
   
   Actual provider availability is determined entirely by which Spring beans 
exist (GoogleOAuth2Provider, GithubOAuth2Provider, hardcoded in the XML) plus 
oauth2.plugins.exclude (see Issue #2) and a different key, 
user.oauth2.providers.order, for ordering.
   
   Steps to Reproduce:
   1. cmk list configurations name=oauth2.plugins — shows google,github.
   2. cmk update configuration name=oauth2.plugins value=github,keycloak  
   
   3. Attempt OAuth2 login with provider=google.
   
   
   
   
   
   
   
   ### What to do about it?
   
   Expected: GitHub provider no longer available, per the setting's name and 
description.
   Actual: No error on update, but github remains fully registered and 
functional — the change is a complete no-op.
   
   Suggested fix: Either wire oauth2.plugins to genuinely gate provider 
registration, or remove it — as-is it presents a non-functional control surface 
that could lead an admin to believe they've disabled a provider when they 
haven't.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to