Failed SAML logins are hard to debug due to wrong error being raised
Summary
When the 'omniauth_provider.required_groups' config option is set, and a SAML assertion does not contain a valid group, the wrong error message is raised.
Authentication proceeds through until it fails here: https://gitlab.com/gitlab-org/gitlab-ee/blob/08b88d899548f535dd5f04761f51248fe9b3e3e9/lib/gitlab/auth/o_auth/user.rb#L37
This raises an error, telling the user signups are disabled: "Signing in using your ... account without a pre-existing GitLab account is not allowed."
Note that this message is displayed regardless of the signup state - the same message is displayed with signups enabled and disabled.
This makes it exceptionally hard to diagnose any faults with our SAML login. This is compounded by a complete absence of useful logs relating to the authentication process.
See also: https://support.gitlab.com/hc/requests/93627
Steps to reproduce
- Configure up a working SAML login with 'required_groups' set
- Log in with a user that is not assigned to group
- Receive wrong error message
What is the current bug behavior?
handle_signup_error is called, and an incorrect error message is displayed
What is the expected correct behavior?
An error that actually reflects the fault that has occured should be displayed
Relevant logs and/or screenshots
I, [2018-03-28T18:49:21.498783 #15645] INFO -- omniauth: (saml) Request phase initiated.
I, [2018-03-28T18:49:30.982273 #15639] INFO -- omniauth: (saml) Callback phase initiated.
Results of GitLab environment info
System information
System:
Proxy: no
Current User: git
Using RVM: no
Ruby Version: 2.3.6p384
Gem Version: 2.6.13
Bundler Version:1.13.7
Rake Version: 12.3.0
Redis Version: 3.2.11
Git Version: 2.14.3
Sidekiq Version:5.0.5
Go Version: unknown
GitLab information
Version: 10.6.2-ee
Revision: d5f09c4
Directory: /opt/gitlab/embedded/service/gitlab-rails
DB Adapter: postgresql
DB Version: 9.6.8
URL: https://git.soc.ja.net
HTTP Clone URL: https://git.soc.ja.net/some-group/some-project.git
SSH Clone URL: git@git.soc.ja.net:some-group/some-project.git
Elasticsearch: no
Geo: no
Using LDAP: no
Using Omniauth: yes
Omniauth Providers: saml
GitLab Shell
Version: 6.0.4
Repository storage paths:
- default: /srv/gitlab/git-data/repositories
Hooks: /opt/gitlab/embedded/service/gitlab-shell/hooks
Git: /opt/gitlab/embedded/bin/git
Results of GitLab application Check
Checking GitLab Shell ...
GitLab Shell version >= 6.0.4 ? ... OK (6.0.4)
Repo base directory exists?
default... yes
Repo storage directories are symlinks?
default... no
Repo paths owned by git:root, or git:git?
default... yes
Repo paths access is drwxrws---?
default... yes
hooks directories in repos are links: ...
5/1 ... ok
6/2 ... ok
6/3 ... ok
6/4 ... ok
6/5 ... ok
6/6 ... ok
7/7 ... ok
6/8 ... ok
6/9 ... ok
10/10 ... ok
8/11 ... repository is empty
Running /opt/gitlab/embedded/service/gitlab-shell/bin/check
Check GitLab API access: OK
Redis available via internal API: OK
Access to /var/opt/gitlab/.ssh/authorized_keys: OK
gitlab-shell self-check successful
Checking GitLab Shell ... Finished
Checking Sidekiq ...
Running? ... yes
Number of Sidekiq processes ... 1
Checking Sidekiq ... Finished
Reply by email is disabled in config/gitlab.yml
Checking LDAP ...
LDAP is disabled in config/gitlab.yml
Checking LDAP ... Finished
Checking GitLab ...
Git configured correctly? ... yes
Database config exists? ... yes
All migrations up? ... yes
Database contains orphaned GroupMembers? ... no
GitLab config exists? ... yes
GitLab config up to date? ... yes
Log directory writable? ... yes
Tmp directory writable? ... yes
Uploads directory exists? ... yes
Uploads directory has correct permissions? ... yes
Uploads directory tmp has correct permissions? ... yes
Init script exists? ... skipped (omnibus-gitlab has no init script)
Init script up-to-date? ... skipped (omnibus-gitlab has no init script)
Projects have namespace: ...
5/1 ... yes
6/2 ... yes
6/3 ... yes
6/4 ... yes
6/5 ... yes
6/6 ... yes
7/7 ... yes
6/8 ... yes
6/9 ... yes
10/10 ... yes
8/11 ... yes
Redis version >= 2.8.0? ... yes
Ruby version >= 2.3.5 ? ... yes (2.3.6)
Git version >= 2.9.5 ? ... yes (2.14.3)
Git user has default SSH configuration? ... yes
Active users: ... 5
Elasticsearch version 5.1 - 5.5? ... skipped (elasticsearch is disabled)
Checking GitLab ... Finished