Looks like the Drupal 7.44 core update may have broken Automatic role population from simpleSAMLphp attributes. Had it configured and working for quite some time. Simplesamlphp still authenticates users properly, it just no longer populates the role specificed (in our case from eduPersonEntitlement attribute). There isn't an error message and no obvious permission setting change.

Maybe related to the "Saving user accounts can sometimes grant the user all roles" https://www.drupal.org/SA-CORE-2016-002
Anybody else seen this? Since the 7.44 is a "Moderately Critical" security update, I'm hesitant to roll it back.

https://www.drupal.org/SA-CORE-2016-002

Comments

treevyr’s picture

Got it working again by enabling "Reevaluate roles every time the user logs in." Both pluses and minus to this, but probably easiest fix.

itsCharlie’s picture

I've tried that but for some reason, it didn't work for me. I've posted my issues in this thread #8.