Hi Team,Multiple users are currently experiencing ...
# gooddata-cloud
a
Hi Team,Multiple users are currently experiencing login issues. We create user accounts through the portal and send out invitations, and they are able to log in successfully on the first day. However, after a day or two, they lose access.For example, for Patrick, I have created approximately 3–4 user accounts. Each time, the user is able to log in initially, but access is lost shortly after, requiring us to create a new account again.This issue is recurring. patrick.berens@submittble.com https://wizehive-zengine.cloud.gooddata.com/
k
This is a known issue pattern in GoodData Cloud. Based on the knowledge sources, the most likely cause is a broken or missing identity mapping (
authId
/ OIDC / Auth0 ID)
. Specifically, when a user is created via the "Create user" button instead of the "Invite user" button, the user is added to the GoodData organization but is not correctly provisioned in the authentication layer (GoodData's managed OIDC/Auth0). This causes login to fail or become unstable shortly after initial access. [invite vs create] Additionally, if invitations are sent but not accepted within 21 days, they expire automatically and the pending user is removed from the organization — requiring a new invitation to be sent. [invitation expiry] Recommended Steps 1. Stop using "Create user" — use "Invite user" instead. The "Invite user" flow correctly provisions the identity in both GoodData and the authentication layer. The "Create user" button does not do this automatically and can result in users being unable to log in or losing access. [invite vs create] 2. Ensure invitations are accepted promptly. Invitations expire after 21 days. If not accepted within that window, the user is removed from the organization and must be re-invited. [invitation expiry] 3. Contact GoodData Support for Patrick's account specifically, providing: ◦ GoodData hostname:
wizehive-zengine.cloud.gooddata.com
◦ Email:
patrick.berens@submittble.com
◦ A note that the user loses access after initial login and that multiple accounts have been recreated ◦ Ask Support to verify whether the user has a valid
authId
/ Auth0 ID in the OIDC layer, and to fix or re-provision the identity if needed. [authId fix] Support can check internal logs and manually correct the identity mapping, which is how similar recurring cases have been resolved. 👍 0 button 👎 0 button ℹ️ Tip: Mention @kapa.ai in the thread for follow-ups. 👀 Our Support team monitors all messages and will jump in if needed.
s
Hi Anjali. While I'm investigating this, could you please clarify: You mentioned email patrick.berens@submittble.com. Could there be a typo, and the correct email is patrick.berens@submittable.com? Thank you in advance.
p
Hi, patrick here. Here are the accounts that got created for me: • patrick.berens@submittable.compatrick.berens+admin@submittable.compatrick.berens+admin2@submittable.com It seems like every time I get signed out, I can’t login again. Each time, the team has to create a new account. I’ve been told that I was created with “Invite User”. I can confirm I got email with invitation and I click “Join Gooddata” button. Any advice would be appreciated. Currently GoodData is not usable for me. Anjali has filed a ticket on basecamp, hopefully we get a response there as well. Thank you!
Screenshot from last email to the admin2 email address. Notice it was 1 day ago, but since being auto-logged out I can’t log back in. It doesn’t seem to recognize my email anymore and recover password link doesn’t work (I don’t receive an email)
👍 1
s
Hi Patrick and Anjali, We looked into this and here is our finding: Your GoodData setup is configured to recognize users who sign in through our Auth0 identity provider (your main login system). However, when you create accounts through the portal, those accounts are being registered under a different login system called Zengine instead. Because of this mismatch, here's what happens: 1. You create account → it gets registered under Zengine 2. User clicks the link and logs in for the first time → it works because he's using the same session from the invitation 3. He comes back the next day and logs in again → this time he goes through Auth0 (your main login system), but GoodData can't find him because his account is registered under Zengine, not Auth0 4. Access is lost, and the only way to temporarily fix it is to create a new account, which repeats the same cycle The fix is straightforward: when creating GoodData accounts for your users, your team needs to register them under Auth0 only. That way, GoodData will always recognize them regardless of when they come back. Please share this with your technical team and ask them to update how user accounts are being created in GoodData.
p
Thanks for investigation. Do you have details have we can achieve this: “when creating GoodData accounts for your users, your team needs to register them under Auth0 only” Is there a technique to ensure we invite user under Auth0, not Zengine?
j
Hi Patrick, Could you please clarify how do you usually create your users? Is it via API? Because it's strange that I see multiple users with your name but with some Auth Zengine ID (probably some OIDC which you used in past?) Because currently, your active IdP is our GoodData managed OIDC. So if you wish to use our managed OIDC you need to trigger proper invitation flow. I have deleted some obsolete users of yours, so you should be able to proceed now and invite your email patrick.berens@submittable.com
Can you please give it a try? invite the user, accept the invitation and log in the platform
If your user gets corrupted eventually, it must be some API call from your end. We will need to investigate this further.
Also, can you confirm if you use JWT flow as well? Or you plan to log in only via credentials?
p
From what I understand, we create users in two ways: 1. Via Embedded 2. GoodData Console UI a. This is how my users have been invited (not via the API). Particularly, the admin ones were never created via embedded I know. Unforunately, my team has gone to bed. I’ll need to try and find someone with access (again, we havne’t been able to invite people for some time it seems so only a few do). Lemme poke around. • If I find someone, if I understand, you are asking them to login to GoodData Console UI and click “invite user”?
I’m literally just trying to look at the Logical Data Model in the UI. If I can get that fixed, I’m happy. if there are embed issues causing conflict, we can figure out how to add them. But right now, every single user we create in the Console UI can’t login after the first login.
j
If you are looking for standard password login using our managed OIDC, then yes - you should trigger the invite flow from the UI.
p
Yeah that’s what we are doing.
j
I would invite you myself, but I don't know which user groups you should belong to so I would rather let it be done from your end.
p
Admin - I should be able to see everything. But whatever minimal permissions for Logicial Data MOdel would be fine too.
1
j
It was not working due to multiple users created in the organization (and some of them deleted in the meantime) so there was some conflict that's why it didn't work. It should work now.
p
Interesting. I’m surprised it was still happening with aliases. Hopefully that fixes it.
j
I found patrick.berens@submittable.com 9 times within your organization
do I have your permission to delete those users with this email address so we can try to invite it again via proper flow?
p
Yes please
I was able to login. Is there a way to see on your side if things look good? I don’t have access to any workspaces it looks like. Everyhting is blank
j
refresh please
p
Thanks! I see workspaces and data model!
👍🏼 1
j
glad to hear
I would really like to understand though why is this happening, I mean why you have so many users etc. If you could provide any additional information about this that would be great 🙂
once possible
p
So my brain defaults to Google SSO when I see the button. So it is possible that first user was created via SSO at first? We also have embedding in our website. Where you can see liveboards, etc. If I had to guess on timeline, it was likely: 1. Try to access via GoodData embedded a. Error: workspace/user not provisioned (we were out of credits around that time) 2. Got access to GoodData embedded - dashboards loaded (I don’t know details here, but I think they just fixed workspace provisioning not user necessarily as that happens JIT I think) 3. At some point, I need access to GoodData. A user gets created. I definitely use Google SSO here first time. 4. Now we run into the loop of can’t login, then recreate user on new email (blocked from using same email), then can’t login, etc, etc. That’s about all I know personally.
👀 1
Do you want me to logout and login to see if it is fixed now? Otherwise, I can screenshot what I need then hope it doens’t break over weekend heh
j
Thank you, we will definitely look into it. And fel free to test the login/logout ofc
p
Was able to logout/login. Thanks so much! I’ll keep ya posted if anything changes, but i’m unblocked. Thanks again!
🙌🏼 1
j
I believe we should be good for now 👍🏼
p
Agreed, have a great weekend!
j
likewise 🙂
@Anjali Mandowara Hello Anjali, if you don't mind, I would like to ask about your current user provisioning process. From the discussion above, I understood that some users should have direct access to the analytics via login through our managed IdP, and then with user creation via API login via JWT into the embedded analytics. We would like to understand the situation for future case evaluation. Thanks a lot.