diff --git a/backend/open_webui/constants.py b/backend/open_webui/constants.py index c6c78de35a..2e5b0ff60c 100644 --- a/backend/open_webui/constants.py +++ b/backend/open_webui/constants.py @@ -58,6 +58,7 @@ class ERROR_MESSAGES(str, Enum): INVALID_TOKEN = 'Your session has expired or the token is invalid. Please sign in again.' INVALID_CRED = 'The email or password provided is incorrect. Please check for typos and try logging in again.' + OAUTH_LOGIN_FAILED = 'Sign-in with your identity provider failed. Please contact your administrator for assistance.' INVALID_EMAIL_FORMAT = "The email format you entered is invalid. Please double-check and make sure you're using a valid email address (e.g., yourname@example.com)." INCORRECT_PASSWORD = 'The password provided is incorrect. Please check for typos and try again.' INVALID_TRUSTED_HEADER = ( diff --git a/backend/open_webui/utils/oauth.py b/backend/open_webui/utils/oauth.py index 061737a35b..281d352716 100644 --- a/backend/open_webui/utils/oauth.py +++ b/backend/open_webui/utils/oauth.py @@ -1917,7 +1917,7 @@ class OAuthManager: detailed_error, exc_info=True, ) - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) except Exception as e: detailed_error = _build_oauth_callback_error_message(e) log.warning( @@ -1926,7 +1926,7 @@ class OAuthManager: detailed_error, exc_info=True, ) - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) # Try to get userinfo from the token first, some providers include it there user_data: UserInfo = token.get('userinfo') @@ -1949,7 +1949,7 @@ class OAuthManager: user_data = user_data['data'] if not user_data: log.warning('OAuth callback failed for provider %s, user data is missing', provider) - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) # Extract the "sub" claim, using custom claim if configured if auth_config.OAUTH_SUB_CLAIM: @@ -1959,7 +1959,7 @@ class OAuthManager: sub = user_data.get(OAUTH_PROVIDERS[provider].get('sub_claim', 'sub')) if not sub: log.warning(f'OAuth callback failed, sub is missing: {user_data}') - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) sub = str(sub) oauth_data = {} @@ -1994,18 +1994,18 @@ class OAuthManager: email = primary_email else: log.warning('No primary email found in GitHub response') - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) else: log.warning('Failed to fetch GitHub email') - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) except Exception as e: log.warning(f'Error fetching GitHub email: {e}') - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) elif ENABLE_OAUTH_EMAIL_FALLBACK: email = f'{provider}@{sub}.local' else: log.warning(f'OAuth callback failed, email is missing: {user_data}') - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) email = email.lower() # If allowed domains are configured, check if the email domain is in the list @@ -2014,7 +2014,7 @@ class OAuthManager: and email.split('@')[-1] not in auth_config.OAUTH_ALLOWED_DOMAINS ): log.warning(f'OAuth callback failed, e-mail domain is not in the list of allowed domains: {user_data}') - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) # Check if the user exists user = await Users.get_user_by_oauth_sub(provider, sub, db=db)