From 67ff390c1cfcb0b2137792e6bf94a923a8b77bd7 Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Sat, 10 Oct 2026 22:56:43 +0200 Subject: [PATCH] fix: OAuth token forwarding and provider sign-out break after a browser restart (#32209) After an OAuth sign-in, the cookies tying the browser to the user's OAuth session were dropped when the browser closed, while the login itself stayed valid for the full JWT lifetime. After a restart the user was still signed in, but model connections and terminal servers using system OAuth got no token, and signing out no longer ended the session at the identity provider. These cookies now last as long as the login again, with and without MFA, as they did in 0.11. --- backend/open_webui/routers/mfa.py | 3 +++ backend/open_webui/utils/oauth.py | 2 ++ 2 files changed, 5 insertions(+) diff --git a/backend/open_webui/routers/mfa.py b/backend/open_webui/routers/mfa.py index 3c65951854..1844fd2fca 100644 --- a/backend/open_webui/routers/mfa.py +++ b/backend/open_webui/routers/mfa.py @@ -23,6 +23,7 @@ from open_webui.models.config import Config from open_webui.models.oauth_sessions import OAuthSessions from open_webui.utils import mfa from open_webui.utils.auth import create_session_response, get_human_user +from open_webui.utils.misc import parse_duration from open_webui.utils.rate_limit import RateLimiter from pydantic import ValidationError from sqlalchemy.exc import SQLAlchemyError @@ -79,12 +80,14 @@ async def finish_login(request, response, user, auth, challenge): if challenge.oauth_session_id: session = await OAuthSessions.get_session_by_id(challenge.oauth_session_id) if session and session.user_id == user.id: + expires_delta = parse_duration(await Config.get('auth.jwt_expiry')) response.set_cookie( 'oauth_session_id', session.id, httponly=True, secure=WEBUI_AUTH_COOKIE_SECURE, samesite=WEBUI_AUTH_COOKIE_SAME_SITE, + max_age=int(expires_delta.total_seconds()) if expires_delta else None, ) clear_challenge_cookie(response) return result diff --git a/backend/open_webui/utils/oauth.py b/backend/open_webui/utils/oauth.py index 04a4831d19..0c7ddc489a 100644 --- a/backend/open_webui/utils/oauth.py +++ b/backend/open_webui/utils/oauth.py @@ -2287,6 +2287,7 @@ class OAuthManager: httponly=True, samesite=WEBUI_AUTH_COOKIE_SAME_SITE, secure=WEBUI_AUTH_COOKIE_SECURE, + **({'max_age': cookie_max_age} if cookie_max_age is not None else {}), ) if ENABLE_OAUTH_ID_TOKEN_COOKIE and token.get('id_token'): response.set_cookie( @@ -2295,6 +2296,7 @@ class OAuthManager: httponly=True, samesite=WEBUI_AUTH_COOKIE_SAME_SITE, secure=WEBUI_AUTH_COOKIE_SECURE, + **({'max_age': cookie_max_age} if cookie_max_age is not None else {}), ) return response