fix: skip blocked OAuth groups when auto-creating groups (#31316)

With ENABLE_OAUTH_GROUP_CREATION on, every group in a user's OAuth claim was created on login, including groups matching OAUTH_BLOCKED_GROUPS. Membership sync already ignored those groups, so the result was empty groups nobody could join. With IdPs that send a user's full directory membership (Keycloak backed by LDAP/AD), one login could fill the group table with thousands of them.

Group creation now applies the same blocklist check as the membership add and remove steps, so a blocked group is never created, joined or left through OAuth. Groups that are not blocked are created as before.

Fixes #29558
This commit is contained in:
Classic298 2026-09-25 06:08:01 +02:00 • committed by GitHub
parent 06bc8cb91e
commit fcb0af3fd4
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -1693,7 +1693,7 @@ class OAuthManager:
log.debug('Using creator ID %s for potential group creation.', creator_id)
for group_name in user_oauth_groups:
if group_name not in all_group_names:
if group_name not in all_group_names and not is_in_blocked_groups(group_name, blocked_groups):
log.info("Group '%s' not found via OAuth claim. Creating group...", group_name)
try:
new_group_form = GroupForm(