mirror of
https://github.com/open-webui/open-webui.git
synced 2026-10-11 03:38:02 +00:00
fix: OAuth token forwarding and provider sign-out break after a browser restart (#32209)
After an OAuth sign-in, the cookies tying the browser to the user's OAuth session were dropped when the browser closed, while the login itself stayed valid for the full JWT lifetime. After a restart the user was still signed in, but model connections and terminal servers using system OAuth got no token, and signing out no longer ended the session at the identity provider. These cookies now last as long as the login again, with and without MFA, as they did in 0.11.
This commit is contained in:
parent
9b130cdeab
commit
67ff390c1c
2 changed files with 5 additions and 0 deletions
|
|
@ -23,6 +23,7 @@ from open_webui.models.config import Config
|
|||
from open_webui.models.oauth_sessions import OAuthSessions
|
||||
from open_webui.utils import mfa
|
||||
from open_webui.utils.auth import create_session_response, get_human_user
|
||||
from open_webui.utils.misc import parse_duration
|
||||
from open_webui.utils.rate_limit import RateLimiter
|
||||
from pydantic import ValidationError
|
||||
from sqlalchemy.exc import SQLAlchemyError
|
||||
|
|
@ -79,12 +80,14 @@ async def finish_login(request, response, user, auth, challenge):
|
|||
if challenge.oauth_session_id:
|
||||
session = await OAuthSessions.get_session_by_id(challenge.oauth_session_id)
|
||||
if session and session.user_id == user.id:
|
||||
expires_delta = parse_duration(await Config.get('auth.jwt_expiry'))
|
||||
response.set_cookie(
|
||||
'oauth_session_id',
|
||||
session.id,
|
||||
httponly=True,
|
||||
secure=WEBUI_AUTH_COOKIE_SECURE,
|
||||
samesite=WEBUI_AUTH_COOKIE_SAME_SITE,
|
||||
max_age=int(expires_delta.total_seconds()) if expires_delta else None,
|
||||
)
|
||||
clear_challenge_cookie(response)
|
||||
return result
|
||||
|
|
|
|||
|
|
@ -2287,6 +2287,7 @@ class OAuthManager:
|
|||
httponly=True,
|
||||
samesite=WEBUI_AUTH_COOKIE_SAME_SITE,
|
||||
secure=WEBUI_AUTH_COOKIE_SECURE,
|
||||
**({'max_age': cookie_max_age} if cookie_max_age is not None else {}),
|
||||
)
|
||||
if ENABLE_OAUTH_ID_TOKEN_COOKIE and token.get('id_token'):
|
||||
response.set_cookie(
|
||||
|
|
@ -2295,6 +2296,7 @@ class OAuthManager:
|
|||
httponly=True,
|
||||
samesite=WEBUI_AUTH_COOKIE_SAME_SITE,
|
||||
secure=WEBUI_AUTH_COOKIE_SECURE,
|
||||
**({'max_age': cookie_max_age} if cookie_max_age is not None else {}),
|
||||
)
|
||||
|
||||
return response
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue