Skip to content

fix[backend](iam): removed idp providers default value on active, so … - #2809

Merged
AlexSanchez-bit merged 1 commit into
release/v12.0.0from
backlog/v12_identity_providers_creation
Oct 1, 2026
Merged

AlexSanchez-bit merged 1 commit into
release/v12.0.0from
backlog/v12_identity_providers_creation

Conversation

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor

No description provided.

…false is not treated as empty and uses the default true
@AlexSanchez-bit AlexSanchez-bit linked an issue Oct 1, 2026 that may be closed by this pull request
2 of 3 tasks
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

🛑 AI review — Sensitive area, extra care recommended

This PR touches critical paths or introduces changes the model cannot judge with sufficient confidence. Review carefully before merging.

🛑 architecture (silas-1.7-pro) — high/critical — please review

Summary: Removes GORM default:true from IAM IdentityProviderConfig.Active, changing persisted schema behavior without migration or compatibility plan.

  • high backend/modules/iam/domain/idp.go:36 — Dropping default:true from Active alters the database default and can create inactive identity provider configs if callers omit the field. Add an explicit migration/backfill or preserve the default and set Active in application code.

🛑 bugs (silas-1.7-pro) — high/critical — please review

Summary: Removing default:true from Active changes new IdP configs to inactive unless explicitly set.

  • high backend/modules/iam/domain/idp.go:36 — The GORM tag for Active no longer declares default:true. New IdentityProviderConfig rows created without explicitly setting Active will default to false instead of true, which can silently deactivate identity providers. Reproduce by creating an IdP config with Active unset after this change; previously the database default made it active.

🛑 security (silas-1.7-pro) — high/critical — please review

Summary: No direct vulnerability identified, but diff touches IAM identity-provider auth path and requires human verification.

No findings.

🔴 go-deps — pending updates

🔍 Discovered 30 Go projects

📦 Dependencies with updates available:

  📁 ./plugins/aws:
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.1 → v1.89.0

  📁 ./plugins/azure:
     - github.com/Azure/azure-sdk-for-go/sdk/azcore: v1.23.1 → v1.23.2

  📁 ./backend:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260819160318-c56c250bc585 → v1.1.36

  📁 ./tools/rulecheck:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent-manager:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./log-input:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./collectors/utmstack:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/forwarder:
     - github.com/netsampler/goflow2: v1.3.7 → v1.3.8
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/as400:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

❌ Please update dependencies before merging.

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor Author

default is not needed since its an expected value, keeping the default value will treat false as a empty value ad setup the default

@AlexSanchez-bit
AlexSanchez-bit merged commit 3aa787b into release/v12.0.0 Oct 1, 2026
1 check passed
@AlexSanchez-bit
AlexSanchez-bit deleted the backlog/v12_identity_providers_creation branch October 1, 2026 17:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

identity providers form lacks of validation of fields

1 participant