From fcb0af3fd4143795646a1aecb89f95a6b1851594 Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Fri, 25 Sep 2026 06:08:01 +0200 Subject: [PATCH] fix: skip blocked OAuth groups when auto-creating groups (#31316) With ENABLE_OAUTH_GROUP_CREATION on, every group in a user's OAuth claim was created on login, including groups matching OAUTH_BLOCKED_GROUPS. Membership sync already ignored those groups, so the result was empty groups nobody could join. With IdPs that send a user's full directory membership (Keycloak backed by LDAP/AD), one login could fill the group table with thousands of them. Group creation now applies the same blocklist check as the membership add and remove steps, so a blocked group is never created, joined or left through OAuth. Groups that are not blocked are created as before. Fixes #29558 --- backend/open_webui/utils/oauth.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/backend/open_webui/utils/oauth.py b/backend/open_webui/utils/oauth.py index 6d7bf67d07..061737a35b 100644 --- a/backend/open_webui/utils/oauth.py +++ b/backend/open_webui/utils/oauth.py @@ -1693,7 +1693,7 @@ class OAuthManager: log.debug('Using creator ID %s for potential group creation.', creator_id) for group_name in user_oauth_groups: - if group_name not in all_group_names: + if group_name not in all_group_names and not is_in_blocked_groups(group_name, blocked_groups): log.info("Group '%s' not found via OAuth claim. Creating group...", group_name) try: new_group_form = GroupForm(