open-webui/backend
Classic298 cd64930c05
fix: MCP OAuth sign-in fails with a state error when the server asks for many scopes (#31894)
Connecting an MCP tool server over OAuth 2.1 failed after signing in at the provider with an "invalid or expired state" error whenever the server advertises a long list of scopes, such as the Google Workspace MCP server with its 42 Google scopes. Open WebUI saved the full authorization link it sends to the provider in the session cookie, which pushed the cookie past the 4096-byte browser limit, so the browser dropped it and Open WebUI could not recognise the user when the provider sent them back. The link is no longer saved there, so the cookie stays at a few hundred bytes even with long scope lists.

Fixes #26382
2026-10-03 17:04:50 +04:00
..
data refac: mv backend files to /open_webui dir 2024-09-04 16:54:48 +02:00
open_webui fix: MCP OAuth sign-in fails with a state error when the server asks for many scopes (#31894) 2026-10-03 17:04:50 +04:00
.dockerignore fix: litellm config issue 2024-02-24 22:35:11 -08:00
.gitignore refac 2024-09-06 04:59:20 +02:00
dev.sh perf: allow disabling websocket per-message-deflate (#28613) 2026-08-24 18:46:07 -04:00
requirements-slim.txt chore: bump pycrdt to 0.14.8 (#31636) 2026-09-30 19:00:23 +04:00
requirements.txt chore: bump pycrdt to 0.14.8 (#31636) 2026-09-30 19:00:23 +04:00
start.sh refac 2026-09-06 16:48:30 -04:00
start_windows.bat chore: drop nltk, unused at the pinned versions (#29725) 2026-09-06 16:39:05 -04:00