Note to first-time contributors: Please open a discussion post in Discussions and describe your changes before submitting a pull request.
Before submitting, make sure you've checked the following:
Target branch: Please verify that the pull request targets the dev branch.
Description: Provide a concise description of the changes made in this pull request.
Changelog: Ensure a changelog entry following the format of Keep a Changelog is added at the bottom of the PR description.
Documentation: Have you updated relevant documentation Open WebUI Docs, or other documentation sources?
Dependencies: Are there any new dependencies? Have you updated the dependency versions in the documentation? (none)
Testing: Have you written and run sufficient tests to validate the changes?(test infrastructure is broken)
Code review: Have you performed a self-review of your code, addressing any coding standard issues and ensuring adherence to the project's coding standards?
Prefix: To clearly categorize this pull request, prefix the pull request title using one of the following:
BREAKING CHANGE: Significant changes that may affect compatibility
build: Changes that affect the build system or external dependencies
ci: Changes to our continuous integration processes or workflows
chore: Refactor, cleanup, or other non-functional code changes
docs: Documentation update or addition
feat: Introduces a new feature or enhancement to the codebase
fix: Bug fix or error correction
i18n: Internationalization or localization changes
perf: Performance improvement
refactor: Code restructuring for better maintainability, readability, or scalability
style: Changes that do not affect the meaning of the code (white space, formatting, missing semi-colons, etc.)
test: Adding missing tests or correcting existing tests
WIP: Work in progress, a temporary label for incomplete or ongoing work
Changelog Entry
Description
This add PKCE support for OIDC logins. PKCE is a requirement by some Auth servers
Added
Support PKCE on OIDC logins by setting OAUTH_CODE_CHALLENGE_METHOD to S256
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.
## 📋 Pull Request Information
**Original PR:** https://github.com/open-webui/open-webui/pull/12563
**Author:** [@thlehmann-ionos](https://github.com/thlehmann-ionos)
**Created:** 4/7/2025
**Status:** ✅ Merged
**Merged:** 4/10/2025
**Merged by:** [@tjbck](https://github.com/tjbck)
**Base:** `dev` ← **Head:** `oidc-add-support-for-pkce`
---
### 📝 Commits (1)
- [`5c658a4`](https://github.com/open-webui/open-webui/commit/5c658a4879d4b7c48cb8ec11b513138d10a8b295) feat(config): add config OAUTH_CODE_CHALLENGE_METHOD
### 📊 Changes
**1 file changed** (+16 additions, -3 deletions)
<details>
<summary>View changed files</summary>
📝 `backend/open_webui/config.py` (+16 -3)
</details>
### 📄 Description
# Pull Request Checklist
### Note to first-time contributors: Please open a discussion post in [Discussions](https://github.com/open-webui/open-webui/discussions) and describe your changes before submitting a pull request.
**Before submitting, make sure you've checked the following:**
- [x] **Target branch:** Please verify that the pull request targets the `dev` branch.
- [x] **Description:** Provide a concise description of the changes made in this pull request.
- [x] **Changelog:** Ensure a changelog entry following the format of [Keep a Changelog](https://keepachangelog.com/) is added at the bottom of the PR description.
- [ ] **Documentation:** Have you updated relevant documentation [Open WebUI Docs](https://github.com/open-webui/docs), or other documentation sources?
- [x] **Dependencies:** Are there any new dependencies? Have you updated the dependency versions in the documentation? _(none)_
- [ ] ~**Testing:** Have you written and run sufficient tests to validate the changes?~ _(test infrastructure is broken)_
- [ ] **Code review:** Have you performed a self-review of your code, addressing any coding standard issues and ensuring adherence to the project's coding standards?
- [x] **Prefix:** To clearly categorize this pull request, prefix the pull request title using one of the following:
- **BREAKING CHANGE**: Significant changes that may affect compatibility
- **build**: Changes that affect the build system or external dependencies
- **ci**: Changes to our continuous integration processes or workflows
- **chore**: Refactor, cleanup, or other non-functional code changes
- **docs**: Documentation update or addition
- **feat**: Introduces a new feature or enhancement to the codebase
- **fix**: Bug fix or error correction
- **i18n**: Internationalization or localization changes
- **perf**: Performance improvement
- **refactor**: Code restructuring for better maintainability, readability, or scalability
- **style**: Changes that do not affect the meaning of the code (white space, formatting, missing semi-colons, etc.)
- **test**: Adding missing tests or correcting existing tests
- **WIP**: Work in progress, a temporary label for incomplete or ongoing work
# Changelog Entry
### Description
- This add PKCE support for OIDC logins. PKCE is a requirement by some Auth servers
### Added
- Support PKCE on OIDC logins by setting `OAUTH_CODE_CHALLENGE_METHOD` to `S256`
---
<sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
📋 Pull Request Information
Original PR: https://github.com/open-webui/open-webui/pull/12563
Author: @thlehmann-ionos
Created: 4/7/2025
Status: ✅ Merged
Merged: 4/10/2025
Merged by: @tjbck
Base:
dev← Head:oidc-add-support-for-pkce📝 Commits (1)
5c658a4feat(config): add config OAUTH_CODE_CHALLENGE_METHOD📊 Changes
1 file changed (+16 additions, -3 deletions)
View changed files
📝
backend/open_webui/config.py(+16 -3)📄 Description
Pull Request Checklist
Note to first-time contributors: Please open a discussion post in Discussions and describe your changes before submitting a pull request.
Before submitting, make sure you've checked the following:
devbranch.Testing: Have you written and run sufficient tests to validate the changes?(test infrastructure is broken)Changelog Entry
Description
Added
OAUTH_CODE_CHALLENGE_METHODtoS256🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.