beezzlot opened a new issue, #13983:
URL: https://github.com/apache/cloudstack/issues/13983
### problem
## Issue Description
After upgrading CloudStack from version **4.21.0.0** to **4.22.1.0**, LDAP
user authentication stopped working for all roles except **Root Admin**.
### Symptoms
1. **Root Admin** — authentication succeeds, UI works correctly
2. **Non-Root Admin users** — authentication appears to succeed, but after
login:
- System cannot load any components in the zone
- UI shows "infinite page loading" that ends in timeout
### Behavior on Fresh Installation
When testing on a new CloudStack 4.22.1.0 instance with LDAP user import,
logs show an error — **malformed LDAP filter syntax** (extra opening
parenthesis `(` at the end):
```log
{"attributes":["uid","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search
request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(
```
### Comparison with Working Version (Root Admin)
On the version where Root Admin works correctly, the filter looks correct:
```log
{"attributes":["cn","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search
request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(cn=*))","level":"info","requestId":"c411e2c7-0468-46af-9120-b7d1fc652f36","scope":"Whole
Subtree","timestamp":"2026-08-26T11:13:44Z","took-ms":15}
```
### versions
## Environment
| Parameter | Value |
|-----------|-------|
| **Product** | Apache CloudStack |
| **Version (before upgrade)** | 4.21.0.0 |
| **Version (after upgrade)** | 4.22.1.0 |
| **Hypervision** | KVM|
### The steps to reproduce the bug
## Steps to Reproduce
### Scenario 1: Upgrade from 4.21.0.0 → 4.22.1.0
1. Install CloudStack 4.21.0.0 with LDAP authentication configured
2. Upgrade to version 4.22.1.0
3. Attempt to login as a user **without** Root Admin role
4. **Observed result:**
- Login appears successful
- UI does not load components (infinite loading → timeout)
### Scenario 2: Fresh Installation 4.22.1.0
1. Deploy new CloudStack 4.22.1.0 instance
2. Configure LDAP authentication (goauthentik or similar server)
3. Import users from LDAP
4. Check CloudStack Management Server logs
5. **Observed result:**
- LDAP query with malformed filter (extra `(` at the end)
```log
{"attributes":["uid","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search
request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(
```
### Comparison with Working Version (Root Admin)
On the version where Root Admin works correctly, the filter looks correct:
```log
{"attributes":["cn","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search
request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(cn=*))","level":"info","requestId":"c411e2c7-0468-46af-9120-b7d1fc652f36","scope":"Whole
Subtree","timestamp":"2026-08-26T11:13:44Z","took-ms":15}
```
### What to do about it?
## Expected Behavior
- LDAP filter should be syntactically correct
- Users of all roles (not only Root Admin) should successfully authenticate
and access the UI
- Filter should match the format:
`(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*))`
## Actual Behavior
- LDAP filter contains syntax error:
`(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(`
- Non-Root Admin users cannot work in UI after authentication
- On fresh installation, LDAP user import fails due to invalid filter
## Questions
1. How to fix permissions in the "upgraded" CloudStack version where only
Root Admin can authenticate without issues?
2. How to fix the issue in fresh installation with the LDAP query error
(malformed filter syntax)?
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]