Conversation
`findUserBySsoIdentity()` chains two `->where()` calls on the DBAL query builder. `where()` *replaces* the previous restriction, so `fieldname = :ssoIdentitiesName` is discarded and the query filters by `dest_id` only (the bound `ssoIdentitiesName` parameter is unused). If the sso-identity object id is referenced by any other relation row of the user class, `count($result) > 1` and the method returns null -> the owning user is not resolved (SSO login / token-cleanup lookup fails). Use `andWhere()`. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Contributor
|
All contributors have signed the CLA ✍️ ✅ |
Contributor
Author
|
I have read the CLA Document and I hereby sign the CLA |
Contributor
Author
|
@solverat Are bug fixes still welcome here, or is the repository dead? If it is dead, I think it should be set to read-only. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bug
SsoIdentityManager::findUserBySsoIdentity()builds the lookup with two consecutive->where()calls:Doctrine DBAL's
QueryBuilder::where()replaces any previously specified restriction, so thefieldname = :ssoIdentitiesNamecondition is dropped and onlydest_idis filtered (the boundssoIdentitiesNameparameter is never used).If the sso-identity object id happens to be referenced by another relation field of the user class, the query returns more than one row,
count($result) === 1is false, and the method returnsnull— the owning user is not resolved, breaking SSO login and the token-cleanup user lookup.Fix
Use
->andWhere()for the second condition so bothfieldnameanddest_idare applied.