fix: OAuth token forwarding and provider sign-out break after a browser restart (#32209)

After an OAuth sign-in, the cookies tying the browser to the user's OAuth session were dropped when the browser closed, while the login itself stayed valid for the full JWT lifetime. After a restart the user was still signed in, but model connections and terminal servers using system OAuth got no token, and signing out no longer ended the session at the identity provider. These cookies now last as long as the login again, with and without MFA, as they did in 0.11.
This commit is contained in:
Classic298 2026-10-10 22:56:43 +02:00 • committed by GitHub
parent 9b130cdeab
commit 67ff390c1c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 5 additions and 0 deletions

View file

@ -23,6 +23,7 @@ from open_webui.models.config import Config
from open_webui.models.oauth_sessions import OAuthSessions
from open_webui.utils import mfa
from open_webui.utils.auth import create_session_response, get_human_user
from open_webui.utils.misc import parse_duration
from open_webui.utils.rate_limit import RateLimiter
from pydantic import ValidationError
from sqlalchemy.exc import SQLAlchemyError
@ -79,12 +80,14 @@ async def finish_login(request, response, user, auth, challenge):
if challenge.oauth_session_id:
session = await OAuthSessions.get_session_by_id(challenge.oauth_session_id)
if session and session.user_id == user.id:
expires_delta = parse_duration(await Config.get('auth.jwt_expiry'))
response.set_cookie(
'oauth_session_id',
session.id,
httponly=True,
secure=WEBUI_AUTH_COOKIE_SECURE,
samesite=WEBUI_AUTH_COOKIE_SAME_SITE,
max_age=int(expires_delta.total_seconds()) if expires_delta else None,
)
clear_challenge_cookie(response)
return result

View file

@ -2287,6 +2287,7 @@ class OAuthManager:
httponly=True,
samesite=WEBUI_AUTH_COOKIE_SAME_SITE,
secure=WEBUI_AUTH_COOKIE_SECURE,
**({'max_age': cookie_max_age} if cookie_max_age is not None else {}),
)
if ENABLE_OAUTH_ID_TOKEN_COOKIE and token.get('id_token'):
response.set_cookie(
@ -2295,6 +2296,7 @@ class OAuthManager:
httponly=True,
samesite=WEBUI_AUTH_COOKIE_SAME_SITE,
secure=WEBUI_AUTH_COOKIE_SECURE,
**({'max_age': cookie_max_age} if cookie_max_age is not None else {}),
)
return response