From 6a2aad92f2049657915e33b78a60cd170407eab9 Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Wed, 30 Sep 2026 17:07:49 +0200 Subject: [PATCH] fix: SSO login failures show the email/password error (#31629) When signing in through an OAuth/OIDC provider failed, for example because the provider denied access, the account had no email or its email domain was not allowed, the login page told the user their email or password was wrong, even though they never typed one. Every such failure now shows "Sign-in with your identity provider failed. Please contact your administrator for assistance." The text is the same for every cause so it does not reveal which check failed, and the exact reason is still written to the server log as a warning. Fixes #31627 --- backend/open_webui/constants.py | 1 + backend/open_webui/utils/oauth.py | 18 +++++++++--------- 2 files changed, 10 insertions(+), 9 deletions(-) diff --git a/backend/open_webui/constants.py b/backend/open_webui/constants.py index c6c78de35a..2e5b0ff60c 100644 --- a/backend/open_webui/constants.py +++ b/backend/open_webui/constants.py @@ -58,6 +58,7 @@ class ERROR_MESSAGES(str, Enum): INVALID_TOKEN = 'Your session has expired or the token is invalid. Please sign in again.' INVALID_CRED = 'The email or password provided is incorrect. Please check for typos and try logging in again.' + OAUTH_LOGIN_FAILED = 'Sign-in with your identity provider failed. Please contact your administrator for assistance.' INVALID_EMAIL_FORMAT = "The email format you entered is invalid. Please double-check and make sure you're using a valid email address (e.g., yourname@example.com)." INCORRECT_PASSWORD = 'The password provided is incorrect. Please check for typos and try again.' INVALID_TRUSTED_HEADER = ( diff --git a/backend/open_webui/utils/oauth.py b/backend/open_webui/utils/oauth.py index 061737a35b..281d352716 100644 --- a/backend/open_webui/utils/oauth.py +++ b/backend/open_webui/utils/oauth.py @@ -1917,7 +1917,7 @@ class OAuthManager: detailed_error, exc_info=True, ) - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) except Exception as e: detailed_error = _build_oauth_callback_error_message(e) log.warning( @@ -1926,7 +1926,7 @@ class OAuthManager: detailed_error, exc_info=True, ) - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) # Try to get userinfo from the token first, some providers include it there user_data: UserInfo = token.get('userinfo') @@ -1949,7 +1949,7 @@ class OAuthManager: user_data = user_data['data'] if not user_data: log.warning('OAuth callback failed for provider %s, user data is missing', provider) - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) # Extract the "sub" claim, using custom claim if configured if auth_config.OAUTH_SUB_CLAIM: @@ -1959,7 +1959,7 @@ class OAuthManager: sub = user_data.get(OAUTH_PROVIDERS[provider].get('sub_claim', 'sub')) if not sub: log.warning(f'OAuth callback failed, sub is missing: {user_data}') - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) sub = str(sub) oauth_data = {} @@ -1994,18 +1994,18 @@ class OAuthManager: email = primary_email else: log.warning('No primary email found in GitHub response') - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) else: log.warning('Failed to fetch GitHub email') - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) except Exception as e: log.warning(f'Error fetching GitHub email: {e}') - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) elif ENABLE_OAUTH_EMAIL_FALLBACK: email = f'{provider}@{sub}.local' else: log.warning(f'OAuth callback failed, email is missing: {user_data}') - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) email = email.lower() # If allowed domains are configured, check if the email domain is in the list @@ -2014,7 +2014,7 @@ class OAuthManager: and email.split('@')[-1] not in auth_config.OAUTH_ALLOWED_DOMAINS ): log.warning(f'OAuth callback failed, e-mail domain is not in the list of allowed domains: {user_data}') - raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED) + raise HTTPException(400, detail=ERROR_MESSAGES.OAUTH_LOGIN_FAILED) # Check if the user exists user = await Users.get_user_by_oauth_sub(provider, sub, db=db)