mirror of
https://github.com/open-webui/open-webui.git
synced 2026-10-05 02:41:34 +00:00
fix: SSO login failures show the email/password error (#31629)
When signing in through an OAuth/OIDC provider failed, for example because the provider denied access, the account had no email or its email domain was not allowed, the login page told the user their email or password was wrong, even though they never typed one. Every such failure now shows "Sign-in with your identity provider failed. Please contact your administrator for assistance." The text is the same for every cause so it does not reveal which check failed, and the exact reason is still written to the server log as a warning. Fixes #31627
This commit is contained in:
parent
b6dfa3799d
commit
6a2aad92f2
2 changed files with 10 additions and 9 deletions
|
|
@ -58,6 +58,7 @@ class ERROR_MESSAGES(str, Enum):
|
|||
|
||||
INVALID_TOKEN = 'Your session has expired or the token is invalid. Please sign in again.'
|
||||
INVALID_CRED = 'The email or password provided is incorrect. Please check for typos and try logging in again.'
|
||||
OAUTH_LOGIN_FAILED = 'Sign-in with your identity provider failed. Please contact your administrator for assistance.'
|
||||
INVALID_EMAIL_FORMAT = "The email format you entered is invalid. Please double-check and make sure you're using a valid email address (e.g., yourname@example.com)."
|
||||
INCORRECT_PASSWORD = 'The password provided is incorrect. Please check for typos and try again.'
|
||||
INVALID_TRUSTED_HEADER = (
|
||||
|
|
|
|||
|
|
@ -1917,7 +1917,7 @@ class OAuthManager:
|
|||
detailed_error,
|
||||
exc_info=True,
|
||||
)
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
|
||||
except Exception as e:
|
||||
detailed_error = _build_oauth_callback_error_message(e)
|
||||
log.warning(
|
||||
|
|
@ -1926,7 +1926,7 @@ class OAuthManager:
|
|||
detailed_error,
|
||||
exc_info=True,
|
||||
)
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
|
||||
|
||||
# Try to get userinfo from the token first, some providers include it there
|
||||
user_data: UserInfo = token.get('userinfo')
|
||||
|
|
@ -1949,7 +1949,7 @@ class OAuthManager:
|
|||
user_data = user_data['data']
|
||||
if not user_data:
|
||||
log.warning('OAuth callback failed for provider %s, user data is missing', provider)
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
|
||||
|
||||
# Extract the "sub" claim, using custom claim if configured
|
||||
if auth_config.OAUTH_SUB_CLAIM:
|
||||
|
|
@ -1959,7 +1959,7 @@ class OAuthManager:
|
|||
sub = user_data.get(OAUTH_PROVIDERS[provider].get('sub_claim', 'sub'))
|
||||
if not sub:
|
||||
log.warning(f'OAuth callback failed, sub is missing: {user_data}')
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
|
||||
sub = str(sub)
|
||||
|
||||
oauth_data = {}
|
||||
|
|
@ -1994,18 +1994,18 @@ class OAuthManager:
|
|||
email = primary_email
|
||||
else:
|
||||
log.warning('No primary email found in GitHub response')
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
|
||||
else:
|
||||
log.warning('Failed to fetch GitHub email')
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
|
||||
except Exception as e:
|
||||
log.warning(f'Error fetching GitHub email: {e}')
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
|
||||
elif ENABLE_OAUTH_EMAIL_FALLBACK:
|
||||
email = f'{provider}@{sub}.local'
|
||||
else:
|
||||
log.warning(f'OAuth callback failed, email is missing: {user_data}')
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
|
||||
|
||||
email = email.lower()
|
||||
# If allowed domains are configured, check if the email domain is in the list
|
||||
|
|
@ -2014,7 +2014,7 @@ class OAuthManager:
|
|||
and email.split('@')[-1] not in auth_config.OAUTH_ALLOWED_DOMAINS
|
||||
):
|
||||
log.warning(f'OAuth callback failed, e-mail domain is not in the list of allowed domains: {user_data}')
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
|
||||
|
||||
# Check if the user exists
|
||||
user = await Users.get_user_by_oauth_sub(provider, sub, db=db)
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue