fix: SSO login failures show the email/password error (#31629)

When signing in through an OAuth/OIDC provider failed, for example because the provider denied access, the account had no email or its email domain was not allowed, the login page told the user their email or password was wrong, even though they never typed one. Every such failure now shows "Sign-in with your identity provider failed. Please contact your administrator for assistance." The text is the same for every cause so it does not reveal which check failed, and the exact reason is still written to the server log as a warning.

Fixes #31627
This commit is contained in:
Classic298 2026-09-30 17:07:49 +02:00 • committed by GitHub
parent b6dfa3799d
commit 6a2aad92f2
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 10 additions and 9 deletions

View file

@ -58,6 +58,7 @@ class ERROR_MESSAGES(str, Enum):
INVALID_TOKEN = 'Your session has expired or the token is invalid. Please sign in again.'
INVALID_CRED = 'The email or password provided is incorrect. Please check for typos and try logging in again.'
OAUTH_LOGIN_FAILED = 'Sign-in with your identity provider failed. Please contact your administrator for assistance.'
INVALID_EMAIL_FORMAT = "The email format you entered is invalid. Please double-check and make sure you're using a valid email address (e.g., yourname@example.com)."
INCORRECT_PASSWORD = 'The password provided is incorrect. Please check for typos and try again.'
INVALID_TRUSTED_HEADER = (

View file

@ -1917,7 +1917,7 @@ class OAuthManager:
detailed_error,
exc_info=True,
)
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
except Exception as e:
detailed_error = _build_oauth_callback_error_message(e)
log.warning(
@ -1926,7 +1926,7 @@ class OAuthManager:
detailed_error,
exc_info=True,
)
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
# Try to get userinfo from the token first, some providers include it there
user_data: UserInfo = token.get('userinfo')
@ -1949,7 +1949,7 @@ class OAuthManager:
user_data = user_data['data']
if not user_data:
log.warning('OAuth callback failed for provider %s, user data is missing', provider)
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
# Extract the "sub" claim, using custom claim if configured
if auth_config.OAUTH_SUB_CLAIM:
@ -1959,7 +1959,7 @@ class OAuthManager:
sub = user_data.get(OAUTH_PROVIDERS[provider].get('sub_claim', 'sub'))
if not sub:
log.warning(f'OAuth callback failed, sub is missing: {user_data}')
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
sub = str(sub)
oauth_data = {}
@ -1994,18 +1994,18 @@ class OAuthManager:
email = primary_email
else:
log.warning('No primary email found in GitHub response')
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
else:
log.warning('Failed to fetch GitHub email')
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
except Exception as e:
log.warning(f'Error fetching GitHub email: {e}')
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
elif ENABLE_OAUTH_EMAIL_FALLBACK:
email = f'{provider}@{sub}.local'
else:
log.warning(f'OAuth callback failed, email is missing: {user_data}')
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
email = email.lower()
# If allowed domains are configured, check if the email domain is in the list
@ -2014,7 +2014,7 @@ class OAuthManager:
and email.split('@')[-1] not in auth_config.OAUTH_ALLOWED_DOMAINS
):
log.warning(f'OAuth callback failed, e-mail domain is not in the list of allowed domains: {user_data}')
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED)
# Check if the user exists
user = await Users.get_user_by_oauth_sub(provider, sub, db=db)