fix: name the secret key when stored MFA secrets cannot be decrypted at startup (#32189)

This commit is contained in:
G30 2026-10-10 12:10:39 -04:00 • committed by GitHub
parent 8aa61fcd6c
commit 170ec28a1a
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -410,7 +410,13 @@ async def validate_mfa_configuration(config: MfaConfigForm | None = None):
if value is not None:
mfa = MfaData.model_validate(value)
if mfa.secret:
decrypt_secret(mfa.secret)
try:
cipher().decrypt(mfa.secret.encode())
except InvalidToken:
raise ValueError(
'Stored MFA secrets cannot be decrypted. '
'Restore the WEBUI_SECRET_KEY or MFA_ENCRYPTION_KEY they were encrypted with.'
) from None
async def update_mfa_config(request, updates: dict) -> bool: