fix: MCP OAuth sign-in fails with a state error when the server asks for many scopes (#31894)

Connecting an MCP tool server over OAuth 2.1 failed after signing in at the provider with an "invalid or expired state" error whenever the server advertises a long list of scopes, such as the Google Workspace MCP server with its 42 Google scopes. Open WebUI saved the full authorization link it sends to the provider in the session cookie, which pushed the cookie past the 4096-byte browser limit, so the browser dropped it and Open WebUI could not recognise the user when the provider sent them back. The link is no longer saved there, so the cookie stays at a few hundred bytes even with long scope lists.

Fixes #26382
This commit is contained in:
Classic298 2026-10-03 15:04:50 +02:00 • committed by GitHub
parent 394295ec76
commit cd64930c05
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -1232,9 +1232,11 @@ class OAuthClientManager:
status_code=status.HTTP_500_INTERNAL_SERVER_ERROR,
detail='OAuth authorization state was not generated',
)
# Keep the URL out of the session cookie; long scope lists push it past the browser size limit
authorization_url = auth_data.pop('url')
auth_data['user_id'] = user_id
await client.save_authorize_data(request, redirect_uri=redirect_uri_str, **auth_data)
return RedirectResponse(auth_data['url'], status_code=302)
return RedirectResponse(authorization_url, status_code=302)
except RuntimeError as e:
# authlib raises RuntimeError('Missing "authorize_url" value') when the
# authorization endpoint could not be resolved from server metadata.