From ba9c96a354b61dfdbb48d18e8f8ddc9305655081 Mon Sep 17 00:00:00 2001 From: Ben Schumacher Date: Thu, 30 Apr 2026 10:46:44 +0200 Subject: [PATCH] fix: detect ADFS when IdpDescriptorURL has no trailing slash (#36333) * fix: detect ADFS when IdpDescriptorURL has no trailing slash The ADFS detection in detectSAMLProviderType was checking for "/adfs/" (with trailing slash) but standard ADFS IdpDescriptorURL values often end with just "/adfs" (e.g. https://adfs.company.com/adfs), causing the provider type to show as "unknown" in support packets. Co-Authored-By: Claude Sonnet 4.6 * fix: lowercase FederationMetadata pattern for case-insensitive matching The normalizedURL is already lowercased, so comparing against the mixed-case literal "/FederationMetadata/" made that branch unreachable. Co-Authored-By: Claude Sonnet 4.6 --------- Co-authored-by: Claude Sonnet 4.6 --- server/channels/app/platform/support_packet.go | 2 +- server/channels/app/platform/support_packet_test.go | 5 +++++ 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/server/channels/app/platform/support_packet.go b/server/channels/app/platform/support_packet.go index 43c8720f33c..e76e82b2b44 100644 --- a/server/channels/app/platform/support_packet.go +++ b/server/channels/app/platform/support_packet.go @@ -432,7 +432,7 @@ func detectSAMLProviderType(idpDescriptorURL string) string { return "Centrify" case strings.Contains(normalizedURL, "/realms/"): return "Keycloak" - case strings.Contains(normalizedURL, "/adfs/") || strings.Contains(normalizedURL, "/FederationMetadata/"): + case strings.Contains(normalizedURL, "/adfs") || strings.Contains(normalizedURL, "/federationmetadata/"): return "ADFS" case strings.Contains(normalizedURL, "shibboleth.net") || strings.Contains(normalizedURL, "/idp/shibboleth"): return "Shibboleth" diff --git a/server/channels/app/platform/support_packet_test.go b/server/channels/app/platform/support_packet_test.go index 570a5cc7a58..1236e79fc7d 100644 --- a/server/channels/app/platform/support_packet_test.go +++ b/server/channels/app/platform/support_packet_test.go @@ -782,6 +782,11 @@ func TestDetectSAMLProviderType(t *testing.T) { idpDescriptorURL: "https://localhost/adfs/services/trust", expectedProvider: "ADFS", }, + { + name: "ADFS provider with bare /adfs path (no trailing slash)", + idpDescriptorURL: "https://adfs.company.com/adfs", + expectedProvider: "ADFS", + }, { name: "Azure AD provider with login.microsoftonline.com", idpDescriptorURL: "https://login.microsoftonline.com/12345/saml2",