Skip to content

REF-15: Fix transposed default audit attribute sources for SESSION_ID and USER - #89

Open
thomasnymand wants to merge 1 commit into
masterfrom
feature/REF-15-audit-attribute-default-swap
Open

REF-15: Fix transposed default audit attribute sources for SESSION_ID and USER#89
thomasnymand wants to merge 1 commit into
masterfrom
feature/REF-15-audit-attribute-default-swap

Conversation

@thomasnymand

Copy link
Copy Markdown
Collaborator

The default lookup specs for the SessionId and ServiceProviderUserId audit attributes were swapped in Configuration.Builder.build():

  • auditRequestAttributeSessionId defaulted to request:remoteUser
  • auditRequestAttributeServiceProviderUserId defaulted to request:sessionId

AuditRequestUtil resolves these specs literally (request:sessionId → session id, request:remoteUser → remote user), so with the default configuration the audit log's SESSION_ID column was populated with the remote user and the USER column with the session id. Nothing downstream compensated — the emitted audit records were genuinely wrong.

Fix

  • Swap the two defaults so each audit column is sourced correctly. This also matches the documented defaults.

Tests

  • Add ConfigurationTest asserting the default audit attribute values (fails against the old transposed defaults, passes with the fix).
  • Register the previously-untested dk.gov.oio.saml.config package in TestSuite so the new test actually runs.

Discovered during the REF-14 documentation review (#88).

Note: two unrelated tests (OIOBPPUtilTest, CRLCheckerTest) fail in the local environment on master as well — JDK 26 JAXB and live-network OCSP respectively — and are not affected by this change.

🤖 Generated with Claude Code

… and USER

The default lookup specs for the SessionId and ServiceProviderUserId audit
attributes were swapped in Configuration.Builder.build(): the SessionId
attribute defaulted to "request:remoteUser" and the ServiceProviderUserId
attribute to "request:sessionId".

Because AuditRequestUtil resolves these specs literally (request:sessionId ->
session id, request:remoteUser -> remote user), the audit log's SESSION_ID
column was populated with the remote user and the USER column with the
session id. Swap the two defaults so each column is sourced correctly, which
also matches the documented defaults.

Add ConfigurationTest asserting the default audit attribute values and
register the previously untested dk.gov.oio.saml.config package in TestSuite.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant