api/v4/groups/ID/saml_group_links/ for deleted links returns unexpected message {"message":"401 Unauthorized"}

Everyone can contribute. Help move this issue forward while earning points, leveling up and collecting rewards.

Original Issue

Problem

There seems to be an issue with SAML Links for groups that are not active in GitLab, and how they are dealt with via the API.

When we use terraform (or the api) we see that api/v4/groups/ID/saml_group_links/[link] returns the message {"message":"401 Unauthorized"} when we know this link does not exist (and would expect a message similar to "group not found").

This is causing us issues now in terraform after a group with SAML links was deleted, but TF is returning the plan as failed with the mentioned message due to the 401 message.

Detected on version 15.4.

Summary

When querying the GitLab API for SAML links associated with groups that are inactive (deleted or do not exist), the API returns a 401 Unauthorized response rather than a more descriptive error such as 404 Not Found.

This causes failures when using Terraform, as it interprets the 401 Unauthorized as an authentication or permissions issue, making resource management challenging when groups or SAML links have been removed.

Steps to Reproduce

  1. Create a SAML Group Link

  2. Run a Terraform plan to reference them

  3. Delete the referenced SAML linked group in Gitlab

  4. Use the GitLab API to query SAML group links for a group that does not exist or has been deleted

    GET /api/v4/groups/ID/saml_group_links/[link]
    1. Observe the response

      {"message":"401 Unauthorized"}
  5. Run a Terraform plan that references the group with SAML links that was deleted

    • Notice the Terraform failure, as it interprets the 401 Unauthorized response as an issue, marking the plan as failed.

What is the Current Bug Behaviour?

  • The API returns 401 Unauthorized for non-existent groups when checking SAML links, which leads Terraform to fail the plan
  • The 401 Unauthorized error message is misleading, as the issue stems from an obsolete group rather than an authorization failure

What is the Expected Correct Behaviour?

The API should return a 404 Not Found error when querying SAML links for an obsolete group

Workaround

  • Current workaround: Manually remove the deleted group resources from the Terraform state file, which allows Terraform to proceed, but this is not ideal for long-term management.

Possible Solution

Edited by 🤖 GitLab Bot 🤖