From cd64930c05263d6f271194b20c8b1951aa771b3a Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Sat, 3 Oct 2026 15:04:50 +0200 Subject: [PATCH] fix: MCP OAuth sign-in fails with a state error when the server asks for many scopes (#31894) Connecting an MCP tool server over OAuth 2.1 failed after signing in at the provider with an "invalid or expired state" error whenever the server advertises a long list of scopes, such as the Google Workspace MCP server with its 42 Google scopes. Open WebUI saved the full authorization link it sends to the provider in the session cookie, which pushed the cookie past the 4096-byte browser limit, so the browser dropped it and Open WebUI could not recognise the user when the provider sent them back. The link is no longer saved there, so the cookie stays at a few hundred bytes even with long scope lists. Fixes #26382 --- backend/open_webui/utils/oauth.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/backend/open_webui/utils/oauth.py b/backend/open_webui/utils/oauth.py index 9155787ec7..bc22cb1434 100644 --- a/backend/open_webui/utils/oauth.py +++ b/backend/open_webui/utils/oauth.py @@ -1232,9 +1232,11 @@ class OAuthClientManager: status_code=status.HTTP_500_INTERNAL_SERVER_ERROR, detail='OAuth authorization state was not generated', ) + # Keep the URL out of the session cookie; long scope lists push it past the browser size limit + authorization_url = auth_data.pop('url') auth_data['user_id'] = user_id await client.save_authorize_data(request, redirect_uri=redirect_uri_str, **auth_data) - return RedirectResponse(auth_data['url'], status_code=302) + return RedirectResponse(authorization_url, status_code=302) except RuntimeError as e: # authlib raises RuntimeError('Missing "authorize_url" value') when the # authorization endpoint could not be resolved from server metadata.