SAML SSO not showing expected message

0
Hi, We are trying to display the message "The authentication was successful, but there is no account available in this application." for user who login in thorugh SAML SSO without having a account in application. As per the mendix SAML docs, disabling the "Allow the module to create users" will show the mentioned message. https://docs.mendix.com/appstore/modules/saml/user-provisioning/#custom-provisioning-rtCurrently its showing "An unexpected error occured while creating a session" message even the setting is disabled.Configuration: Logs: INFO - UserCommons: Started user creationWARNING - UserCommons: User creation is currently disabled due to the inactive status of the 'Allow module to Create users' setting in the Configuration. Please enable this setting to proceed with user creationINFO - SAML_SSO: Failed: Could not create a session for the provided user principal 'username@domain.com': User lookup of 'Name' failed, this user principal does not exist in the Mx database. at UserCommons.CreateOrUpdateUser (JavaAction : 'CreateUserRecord')From the logs it shows warning to enable the settings, If the account not present it should display no account available. Anyone knows a workaround or fix for this issue?SAML Version: 4.2.3User Commons Version: 2.4.0
asked
1 answers
0

The SAML configuration looks correct to me. With “Allow the module to create users” disabled, a successful SAML authentication without a matching Mendix account should result in:

“The authentication was successful, but there is no account available in this application.”


Mendix's SAML troubleshooting documentation also describes this as the expected behavior.


The interesting part is your log:

User lookup of 'Name' failed, this user principal does not exist in the Mx database.


This suggests the SAML assertion is being processed correctly, but the failure happens in the UserCommons CreateUserRecord/session creation flow. Since SAML 4.2.3 and UserCommons 2.4.0 are the relevant current versions, I would first verify the exact Mendix runtime version and confirm there are no older SAML/UserCommons Java libraries left in userlib.


If everything is on the supported versions and the issue is reproducible with a user that definitely does not exist, I would raise this with Mendix Support because the observed behavior differs from the documented SAML error handling.


Kindly mark this as the accepted answer if it helps.

answered