Bug 40613 - Logout from SAML Session leads to /univention-management-console/ login screen
Logout from SAML Session leads to /univention-management-console/ login screen
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: SAML
UCS 4.1
Other Linux
: P5 normal (vote)
: UCS 4.1-1-errata
Assigned To: Florian Best
Johannes Keiser
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2016-02-09 17:13 CET by Michel Smidt
Modified: 2016-03-21 09:05 CET (History)
2 users (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michel Smidt 2016-02-09 17:13:37 CET
Noticed in a customer workshop by a participant.

When I logout from the univention-management-console with a SAML Session I will be redirected to the login page (LDAP/PAM) under /univention-management-console/.
But the right logout redirect would be the SP login screen under /univention-management-console/saml/

In this case the customer only want SAML Login by default. So, we set ucr set ucs/web/overview/entries/admin/umc/link='/univention-management-console/saml/'
Comment 1 Florian Best univentionstaff 2016-02-09 17:26:13 CET
It would be correct only in your case/wish!
We could make the Logout-Location configurable via UCR.
Changing it to always /univention-management-console/saml/ would not be nice.
Comment 2 Michel Smidt 2016-02-10 08:59:36 CET
(In reply to Florian Best from comment #1)
> It would be correct only in your case/wish!
> We could make the Logout-Location configurable via UCR.
> Changing it to always /univention-management-console/saml/ would not be nice.

Yes, sure. Configurable via UCR would be fine.
Comment 3 Florian Best univentionstaff 2016-03-07 10:51:01 CET
Fixed:
ucr set umc/logout/location=/univention-management-console/saml/

univention-management-console-frontend.yaml:
r67952 | YAML Bug #35407 Bug #40613

univention-management-console-frontend (5.0.63-29):
r67950 | Bug #40613: make the logout redirect location configurable
Comment 4 Johannes Keiser univentionstaff 2016-03-11 18:35:01 CET
CHANGES: OK (redirects as stated in the ucr variable)
YAML: OK (added latest package version)
Comment 5 Florian Best univentionstaff 2016-03-18 06:49:38 CET
<http://errata.software-univention.de/ucs/4.1/132.html>
Comment 6 Michel Smidt 2016-03-21 09:05:42 CET
Thx. Works like a charm!
I only had to restart the univention-management-console-web-server & univention-management-console-server.