Bug 53617 - Burger menu of ucs-sso contains "login" button
Summary: Burger menu of ucs-sso contains "login" button
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: SAML
Version: UCS 4.4
Hardware: Other Linux
: P5 normal
Target Milestone: UCS 4.4-8-errata
Assignee: Johannes Keiser
QA Contact: Dirk Wiesenthal
URL:
Keywords:
Depends on:
Blocks: 53728
  Show dependency treegraph
 
Reported: 2021-07-27 14:55 CEST by Sönke Schwardt-Krummrich
Modified: 2021-09-01 17:39 CEST (History)
1 user (show)

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 4: Minor Usability: Impairs usability in secondary scenarios
Who will be affected by this bug?: 3: Will affect average number of installed domains
How will those affected feel about the bug?: 2: A Pain – users won’t like this once they notice it
User Pain: 0.137
Enterprise Customer affected?:
School Customer affected?: Yes
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Usability
Customer ID: 02149
Max CVSS v3 score:


Attachments
Login button on login screen (160.95 KB, video/mp4)
2021-07-27 14:55 CEST, Sönke Schwardt-Krummrich
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Sönke Schwardt-Krummrich univentionstaff 2021-07-27 14:55:15 CEST
Created attachment 10789 [details]
Login button on login screen

Some larger school customers operate several portal servers that are run behind a load balancer under a uniform URL, e.g. https://portal.kunde.ucs.
The individual portal servers are *not* directly accessible from outside with their FQDN (e.g. server0815.kunde.ucs).
If a user starts a login attempt via the SAML login (see video), a "Login"/"Anmelden" entry is still displayed in the burger menu, pointing to the non-SSO login of the portal server in question 
→ https://server0815.kunde.ucs/univention/login/

This leads to confusion because the host is not directly accessible and an error message is displayed in the browser accordingly.
The problem is somewhat exacerbated if, for example, 2FA plugins for SSO are used, the first auth step has already been completed and the second factor is requested in a second step. Users then search the burger menu and find an inappropriate menu entry.
Comment 2 Johannes Keiser univentionstaff 2021-08-31 15:11:33 CEST
The 'Login' and 'Logout' menu entries are no longer shown on the login site

dd7adcda5f Bug #53617: yaml
bc431d04f6 Bug #53617: version bump
395134d420 Bug #53617: yaml
497fef7f68 Bug #53617: hide 'Login'/'Logout' menu entry on login site

Successful build
Package: univention-management-console
Version: 11.0.6-17A~4.4.0.202108311507
Branch: ucs_4.4-0
Scope: errata4.4-8

Successful build
Package: univention-web
Version: 3.0.6-10A~4.4.0.202108311500
Branch: ucs_4.4-0
Scope: errata4.4-8
Comment 3 Dirk Wiesenthal univentionstaff 2021-09-01 01:28:39 CEST
Login Menu: OK
SAML Menu: OK
YAML: OK