SAML SSO User Creation Causes Keycloak External ID and Sunbird User ID Mismatch Leading to Enrollment and Certificate Failures #843
suraj-tekdi
started this conversation in
General Discussion
Replies: 1 comment
|
Hi @suraj-tekdi , two quick things we need to confirm: 1. JWT 2. Keycloak user check |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Issue: SAML SSO User Creation Causes Keycloak External ID and Sunbird User ID Mismatch Leading to Enrollment and Certificate Failures
Environment
/api/user/v1/sso/createProblem Statement
When a user logs in through SAML SSO, Keycloak generates an external identity (available in JWT
subclaim).Example:
We create the corresponding Sunbird user using:
Request:
{ "params": { "signupType": "sso" }, "request": { "firstName": "User Name", "channel": "nulp-mainorg", "externalIds": [ { "id": "e78c30c5-0ad9-4afe-a99d-406051fb4c69", "provider": "nulp-mainorg", "idType": "nulp-mainorg" } ], "email": "user@example.com", "emailVerified": true } }Response:
{ "result": { "userId": "6121eabc-7a56-4108-8e74-72bc8e936119" } }This creates the expected mapping:
Verified in Cassandra:
Result:
Issue Observed
While the SSO mapping is created correctly, course enrollment is getting stored against the external identity instead of the actual Sunbird user ID.
Enrollment request:
Payload:
{ "request": { "courseId": "do_114582226199396352116", "userId": "6121eabc-7a56-4108-8e74-72bc8e936119", "batchId": "0145848852057456642" } }However, Cassandra stores:
instead of:
Verified in:
Multiple enrollments exist against the external ID.
No enrollments exist for:
Impact
Certificate generation fails because the certificate processor expects Sunbird user IDs.
Observed error:
Certificate job payload contains:
The processor attempts:
which fails because the API expects a Sunbird user ID, not an external identity.
Expected Behaviour
After SSO login:
Expected enrollment record:
Actual enrollment record:
Request
Please clarify:
/learner/course/v1/enrolis expected to use the authenticated actor ID instead ofrequest.userId./api/user/v1/sso/createrequire additional user resolution before enrollment.All reactions