diff --git a/backend/open_webui/routers/mfa.py b/backend/open_webui/routers/mfa.py index 3c65951854..1844fd2fca 100644 --- a/backend/open_webui/routers/mfa.py +++ b/backend/open_webui/routers/mfa.py @@ -23,6 +23,7 @@ from open_webui.models.config import Config from open_webui.models.oauth_sessions import OAuthSessions from open_webui.utils import mfa from open_webui.utils.auth import create_session_response, get_human_user +from open_webui.utils.misc import parse_duration from open_webui.utils.rate_limit import RateLimiter from pydantic import ValidationError from sqlalchemy.exc import SQLAlchemyError @@ -79,12 +80,14 @@ async def finish_login(request, response, user, auth, challenge): if challenge.oauth_session_id: session = await OAuthSessions.get_session_by_id(challenge.oauth_session_id) if session and session.user_id == user.id: + expires_delta = parse_duration(await Config.get('auth.jwt_expiry')) response.set_cookie( 'oauth_session_id', session.id, httponly=True, secure=WEBUI_AUTH_COOKIE_SECURE, samesite=WEBUI_AUTH_COOKIE_SAME_SITE, + max_age=int(expires_delta.total_seconds()) if expires_delta else None, ) clear_challenge_cookie(response) return result diff --git a/backend/open_webui/utils/oauth.py b/backend/open_webui/utils/oauth.py index 04a4831d19..0c7ddc489a 100644 --- a/backend/open_webui/utils/oauth.py +++ b/backend/open_webui/utils/oauth.py @@ -2287,6 +2287,7 @@ class OAuthManager: httponly=True, samesite=WEBUI_AUTH_COOKIE_SAME_SITE, secure=WEBUI_AUTH_COOKIE_SECURE, + **({'max_age': cookie_max_age} if cookie_max_age is not None else {}), ) if ENABLE_OAUTH_ID_TOKEN_COOKIE and token.get('id_token'): response.set_cookie( @@ -2295,6 +2296,7 @@ class OAuthManager: httponly=True, samesite=WEBUI_AUTH_COOKIE_SAME_SITE, secure=WEBUI_AUTH_COOKIE_SECURE, + **({'max_age': cookie_max_age} if cookie_max_age is not None else {}), ) return response