api/v4/groups/ID/saml_group_links/ for deleted links returns unexpected message {"message":"401 Unauthorized"}
Everyone can contribute. Help move this issue forward while earning points, leveling up and collecting rewards.
Original Issue
Problem
There seems to be an issue with SAML Links for groups that are not active in GitLab, and how they are dealt with via the API.
When we use terraform (or the api) we see that api/v4/groups/ID/saml_group_links/[link] returns the message {"message":"401 Unauthorized"} when we know this link does not exist (and would expect a message similar to "group not found").
This is causing us issues now in terraform after a group with SAML links was deleted, but TF is returning the plan as failed with the mentioned message due to the 401 message.
Detected on version 15.4.
Summary
When querying the GitLab API for SAML links associated with groups that are inactive (deleted or do not exist), the API returns a 401 Unauthorized response rather than a more descriptive error such as 404 Not Found.
This causes failures when using Terraform, as it interprets the 401 Unauthorized as an authentication or permissions issue, making resource management challenging when groups or SAML links have been removed.
Steps to Reproduce
-
Create a SAML Group Link
-
Run a Terraform plan to reference them
-
Delete the referenced SAML linked group in Gitlab
-
Use the GitLab API to query SAML group links for a group that does not exist or has been deleted
GET /api/v4/groups/ID/saml_group_links/[link]-
Observe the response
{"message":"401 Unauthorized"}
-
-
Run a Terraform plan that references the group with SAML links that was deleted
- Notice the Terraform failure, as it interprets the
401 Unauthorizedresponse as an issue, marking the plan as failed.
- Notice the Terraform failure, as it interprets the
What is the Current Bug Behaviour?
- The API returns
401 Unauthorizedfor non-existent groups when checking SAML links, which leads Terraform to fail the plan - The
401 Unauthorizederror message is misleading, as the issue stems from an obsolete group rather than an authorization failure
What is the Expected Correct Behaviour?
The API should return a 404 Not Found error when querying SAML links for an obsolete group
Workaround
- Current workaround: Manually remove the deleted group resources from the Terraform state file, which allows Terraform to proceed, but this is not ideal for long-term management.
Possible Solution
- See this comment
- Relevant tests