mirror of
https://github.com/go-gitea/gitea.git
synced 2026-07-21 04:02:17 -05:00
OAuth2 login broken for new users #7746
Closed
opened 2025-11-02 07:35:15 -06:00 by GiteaMirror
·
11 comments
No Branch/Tag Specified
main
release/v1.25
release/v1.24
release/v1.23
release/v1.22
release/v1.21
release/v1.20
release/v1.19
release/v1.18
release/v1.17
release/v1.16
release/v1.15
release/v1.14
release/v1.13
release/v1.12
release/v1.11
release/v1.10
release/v1.9
release/v1.8
v1.25.3
v1.25.2
v1.25.1
v1.25.0
v1.24.7
v1.25.0-rc0
v1.26.0-dev
v1.24.6
v1.24.5
v1.24.4
v1.24.3
v1.24.2
v1.24.1
v1.24.0
v1.23.8
v1.24.0-rc0
v1.25.0-dev
v1.23.7
v1.23.6
v1.23.5
v1.23.4
v1.23.3
v1.23.2
v1.23.1
v1.23.0
v1.23.0-rc0
v1.24.0-dev
v1.22.6
v1.22.5
v1.22.4
v1.22.3
v1.22.2
v1.22.1
v1.22.0
v1.23.0-dev
v1.22.0-rc1
v1.21.11
v1.22.0-rc0
v1.21.10
v1.21.9
v1.21.8
v1.21.7
v1.21.6
v1.21.5
v1.21.4
v1.21.3
v1.21.2
v1.20.6
v1.21.1
v1.21.0
v1.21.0-rc2
v1.21.0-rc1
v1.20.5
v1.22.0-dev
v1.21.0-rc0
v1.20.4
v1.20.3
v1.20.2
v1.20.1
v1.20.0
v1.19.4
v1.21.0-dev
v1.20.0-rc2
v1.20.0-rc1
v1.20.0-rc0
v1.19.3
v1.19.2
v1.19.1
v1.19.0
v1.19.0-rc1
v1.20.0-dev
v1.19.0-rc0
v1.18.5
v1.18.4
v1.18.3
v1.18.2
v1.18.1
v1.18.0
v1.17.4
v1.18.0-rc1
v1.19.0-dev
v1.18.0-rc0
v1.17.3
v1.17.2
v1.17.1
v1.17.0
v1.17.0-rc2
v1.16.9
v1.17.0-rc1
v1.18.0-dev
v1.16.8
v1.16.7
v1.16.6
v1.16.5
v1.16.4
v1.16.3
v1.16.2
v1.16.1
v1.16.0
v1.15.11
v1.17.0-dev
v1.16.0-rc1
v1.15.10
v1.15.9
v1.15.8
v1.15.7
v1.15.6
v1.15.5
v1.15.4
v1.15.3
v1.15.2
v1.15.1
v1.14.7
v1.15.0
v1.15.0-rc3
v1.14.6
v1.15.0-rc2
v1.14.5
v1.16.0-dev
v1.15.0-rc1
v1.14.4
v1.14.3
v1.14.2
v1.14.1
v1.14.0
v1.13.7
v1.14.0-rc2
v1.13.6
v1.13.5
v1.14.0-rc1
v1.15.0-dev
v1.13.4
v1.13.3
v1.13.2
v1.13.1
v1.13.0
v1.12.6
v1.13.0-rc2
v1.14.0-dev
v1.13.0-rc1
v1.12.5
v1.12.4
v1.12.3
v1.12.2
v1.12.1
v1.11.8
v1.12.0
v1.11.7
v1.12.0-rc2
v1.11.6
v1.12.0-rc1
v1.13.0-dev
v1.11.5
v1.11.4
v1.11.3
v1.10.6
v1.12.0-dev
v1.11.2
v1.10.5
v1.11.1
v1.10.4
v1.11.0
v1.11.0-rc2
v1.10.3
v1.11.0-rc1
v1.10.2
v1.10.1
v1.10.0
v1.9.6
v1.9.5
v1.10.0-rc2
v1.11.0-dev
v1.10.0-rc1
v1.9.4
v1.9.3
v1.9.2
v1.9.1
v1.9.0
v1.9.0-rc2
v1.10.0-dev
v1.9.0-rc1
v1.8.3
v1.8.2
v1.8.1
v1.8.0
v1.8.0-rc3
v1.7.6
v1.8.0-rc2
v1.7.5
v1.8.0-rc1
v1.9.0-dev
v1.7.4
v1.7.3
v1.7.2
v1.7.1
v1.7.0
v1.7.0-rc3
v1.6.4
v1.7.0-rc2
v1.6.3
v1.7.0-rc1
v1.7.0-dev
v1.6.2
v1.6.1
v1.6.0
v1.6.0-rc2
v1.5.3
v1.6.0-rc1
v1.6.0-dev
v1.5.2
v1.5.1
v1.5.0
v1.5.0-rc2
v1.5.0-rc1
v1.5.0-dev
v1.4.3
v1.4.2
v1.4.1
v1.4.0
v1.4.0-rc3
v1.4.0-rc2
v1.3.3
v1.4.0-rc1
v1.3.2
v1.3.1
v1.3.0
v1.3.0-rc2
v1.3.0-rc1
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.2.0-rc3
v1.2.0-rc2
v1.1.4
v1.2.0-rc1
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.99
Labels
Clear labels
$20
$250
$50
$500
backport/done
💎 Bounty
docs-update-needed
good first issue
hacktoberfest
issue/bounty
issue/confirmed
issue/critical
issue/duplicate
issue/needs-feedback
issue/not-a-bug
issue/regression
issue/stale
issue/workaround
lgtm/need 2
modifies/api
modifies/translation
outdated/backport/v1.18
outdated/theme/markdown
outdated/theme/timetracker
performance/bigrepo
performance/cpu
performance/memory
performance/speed
pr/breaking
proposal/accepted
proposal/rejected
pr/wip
pull-request
reviewed/wontfix
💰 Rewarded
skip-changelog
status/blocked
topic/accessibility
topic/api
topic/authentication
topic/build
topic/code-linting
topic/commit-signing
topic/content-rendering
topic/deployment
topic/distribution
topic/federation
topic/gitea-actions
topic/issues
topic/lfs
topic/mobile
topic/moderation
topic/packages
topic/pr
topic/projects
topic/repo
topic/repo-migration
topic/security
topic/theme
topic/ui
topic/ui-interaction
topic/ux
topic/webhooks
topic/wiki
type/bug
type/deprecation
type/docs
type/enhancement
type/feature
type/miscellaneous
type/proposal
type/question
type/refactoring
type/summary
type/testing
type/upstream
Mirrored from GitHub Pull Request
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/gitea#7746
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @sanderfoobar on GitHub (Aug 24, 2021).
information
d22cb600edc2605bd8be25c9079a5ce2c6643547(recent master i think)description
my.domain.com(gitea)login.my.domain.com(keycloak)This flow used to work on Gitea
1.13. The (new) gitea user would get a "registration screen" upon redirection from SSO. I recently upgraded to1.14and it broke. Today I "upgraded" to1.15and that also does not work.The error from logs:
The error is:
UserSignIn: could not find a matching session for this request.Which is this bit of code:
https://github.com/markbates/goth/blob/716f16114cccbcbb9ae15099ec2ffa3b006e43eb/gothic/gothic.go#L321-L331
Here is my (truncated) config:
@zeripath commented on GitHub (Aug 26, 2021):
What is your oauth2 type? This works for Github.
@sanderfoobar commented on GitHub (Aug 26, 2021):
OpenID Connect, the confidential access flow.
@zeripath commented on GitHub (Aug 26, 2021):
Did you do a dump and restore? Or just plainly migrate your db?
@lunny commented on GitHub (Aug 27, 2021):
Please try serval times, this maybe a known issue.
@sanderfoobar commented on GitHub (Aug 27, 2021):
How I update between gitea versions:
So I'm not doing any database migration, not sure if it is necessary? I assumed gitea does so automatically. If I try to go back in versions (From
mastertov1.14.0) I get this error:Login will not work. See steps above of what happens.
@zeripath commented on GitHub (Aug 27, 2021):
OK so it was just a plain automatic migration.
Can you confirm on the administrator authentication sources pages that the source has the correct details?
@sanderfoobar commented on GitHub (Aug 27, 2021):
In the administration panel it has the correct authentication source details:
OAuth2OpenID Connectgitearedactedhttps://login.my.domain.com/auth/realms/master/.well-known/openid-configurationWhen I login with my own (admin) account, I am using the OIDC provider to login, so login for existing users works, just the creation of new user accounts does not (that are created at the Authentication Source).
I am not a Go programmer but I will try to debug a bit now.
@zeripath commented on GitHub (Aug 27, 2021):
OK so we login correctly if the user exists. That's good because it indicates that it's not necessarily something that's broken by the recent changes.
I'm guess I'm just not certain what to do to work this out.
My suspicion is that the problem is going to be related to the cookies. We currently don't provide way to set the cookie configuration but I'm just not sure if that's the problem.
Unfortunately this means we're going to have to add some logging into this area of code to debug this tightly.
@sanderfoobar commented on GitHub (Aug 27, 2021):
Ok, seems I had 3 issues:
UserSignIn: could not find a matching session for this requesterror, like @lunny mentioned, can be fixed by clicking on OpenID login twice (first time there is the error, second time it works).emailclaim, I had to manually add it so it is included when/tokenis called. By default the OIDC/userinfoendpoint is not reachable for Gitea (I think) because Gitea only asks for theopenidscope when redirecting to Keycloak so it can never get the email.[oauth2_client]configuration inapp.inineeded some modificationsAnd yes, the
UserSignIn: could not find a matching session for this requesterror is still an issue but is easily fixed for my users (ill tell them to login multiple times).thanks for the help
@zeripath commented on GitHub (Aug 27, 2021):
In terms of scopes requested you can set the OPENID_CONNECT_SCOPES to ask for additional scopes and my pr #16766 will allow you set this on a per source level.
In terms of userinfo I'll have a look at this and see what info we get back from openid
What were these?
I'm still kinda confused by what could be causing this. Maybe we just need to redirect back if we fail.
I do think we need to sort something out regarding the cookie though as I think it's a potentially a serious issue.
@sanderfoobar commented on GitHub (Aug 28, 2021):
Changed it to this:
Previously I had
USERNAME = useridwhich uses thesubclaim, which is a UUIDv4, which doesn't make for nice usernames ;)No idea, but surely it must be something regarding how Gitea uses Goth (goth stores stuff in the session)