Skip to content

Fix: SSO identity lookup drops the fieldname filter (where() overrides where()) - #224

Open
blankse wants to merge 1 commit into
dachcom-digital:masterfrom
blankse:fix/sso-identity-fieldname-filter
Open

blankse wants to merge 1 commit into
dachcom-digital:masterfrom
blankse:fix/sso-identity-fieldname-filter

Conversation

@blankse

@blankse blankse commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Bug

SsoIdentityManager::findUserBySsoIdentity() builds the lookup with two consecutive ->where() calls:

$qb->select('src_id')
   ->from('object_relations_' . $userClass::classId())
   ->where('fieldname = :ssoIdentitiesName')
   ->where('dest_id = :ssoIdentitiesId');

Doctrine DBAL's QueryBuilder::where() replaces any previously specified restriction, so the fieldname = :ssoIdentitiesName condition is dropped and only dest_id is filtered (the bound ssoIdentitiesName parameter is never used).

If the sso-identity object id happens to be referenced by another relation field of the user class, the query returns more than one row, count($result) === 1 is false, and the method returns null — the owning user is not resolved, breaking SSO login and the token-cleanup user lookup.

Fix

Use ->andWhere() for the second condition so both fieldname and dest_id are applied.

`findUserBySsoIdentity()` chains two `->where()` calls on the DBAL query
builder. `where()` *replaces* the previous restriction, so
`fieldname = :ssoIdentitiesName` is discarded and the query filters by
`dest_id` only (the bound `ssoIdentitiesName` parameter is unused). If the
sso-identity object id is referenced by any other relation row of the user
class, `count($result) > 1` and the method returns null -> the owning user is
not resolved (SSO login / token-cleanup lookup fails). Use `andWhere()`.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@blankse

blankse commented Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

I have read the CLA Document and I hereby sign the CLA

@blankse

blankse commented Jul 23, 2026

Copy link
Copy Markdown
Contributor Author

@solverat Are bug fixes still welcome here, or is the repository dead? If it is dead, I think it should be set to read-only.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant