Skip to content

Application policies mode all broken when using group and user filter #17484

@OCram85

Description

@OCram85

Describe the bug
After updating to 2025.8.4 my existing application policies fails when using:

  • a standard group policy - use a ldap group or local group
  • a standard user policy - use a ldap user or local user
  • using policy mode ALL

You can see and use those application if you're member in group, although you're note the given user from the second condition

To Reproduce
Steps to reproduce the behavior:

You can create any application like described above.

Expected behavior
The application should only be visible and consumable by the user added in the user policy

Screenshots

Test App:
Image

Policy Mode:
Image

Policy Details:
Image

Test group members:
Image

✅ Test with valid user. user is in group and dedicated selected:
Image

🛑 Test with user which is group member not not used in additional policy:
Image

🛑 Same test like above but with ldap synced user:
Image

✅ test with any other use not in group or used in additional policy:
Image

Logs
Output of docker-compose logs or kubectl logs respectively

Version and Deployment (please complete the following information):

  • authentik version: 2025.8.4
  • Deployment: docker-compose

Additional context

  • latest known authentik version in which this use-case worked: 2024.8.4

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingbug/confirmedConfirmed bugs

    Type

    No type

    Projects

    Status

    Done

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions