mirror of
https://github.com/advplyr/audiobookshelf.git
synced 2026-05-30 23:40:40 +02:00
[Bug]: OIDC login does not work with Nextcloud #1598
Closed
opened 2026-04-24 23:51:15 +02:00 by adam
·
5 comments
No Branch/Tag Specified
master
book_tags_genres_dedupe
episode_download_fallback
Issue-4540-SortBy-StartedDate-and-FinishedDate
episode_meta_tagging
fix_authorize_race_condition
redirect_transcode_requests
progress_updated_sort
fix_ereader_socket_event
fix_change_empty_root_password
fix_podcast_session_track_index
fix_set_token
session_modal_user
localize_durations
fix_oidc_create_user
jwt_auth_refactor
fix_scanner_deleting_single_file_books
fix_mediaprogress_updatedat_2
experimental_next_client
podcast_episode_duration
episode-timestamps-clickable
book_author_secondary_sort_title
podcast_useragents
pathexists_user_access
fix_pathexists_join
book_author_secondary_sort
clean_duplicate_mediaprogress
sanitize_html_description
trix_prevent_attachments
check_path_api_fix
fix_mediaprogress_updatedat
increase_express_json_limit
fix_dockerfile_nunicode
search_episodes
audiobook_tools_update
episode_secondary_sorts
hls_stream_url_update
new_session_track_endpoint
audiobook_tools_enhancements
watcher_rescans_update
player_track_tooltip
fix_exclude_prefixes_crash
socket_item_events
fix_podcast_episode_scanner_promise
new_stats_controller
count_cache_for_userpermissions
parsing-opf-v3
validate_migration_files
fix-quick-match-all-crash
fix-chapter-end-sleep-timer
stringify_sequelize_query
remove-col-ambiguity
fix_next_prev_edit_description
details_trim_whitespace
fix_content_url_basepath
fix_logger_fatal
progress_bar_visibility
batch-edit-populate-map-details
feed_generator_updates
bookmark-modal-updates
migrate-library-item-in-scanner
migrate-new-library-items
migrate-podcasts-new-library-item-2
migrate-podcasts-new-library-item
fix-remove-episode-from-playlist
playback-session-use-new-library-item
refactor-library-item
fix-heatmap-caption
feed-episodes-upsert
share-media-player-media-session-api
remove-old-playlist
remove_old_collection_object
plugin-implementation-demo
feed_migration
refactor-feeds-from-item
fix_remove_authors_no_books
v2.17.3-fk-constraints-migration
migrations-first-upgrade
sqlite_2
feature/nuxt-target-server
waveform
sqlite
playlists
video
v2.35.1
v2.35.0
v2.34.0
v2.33.2
v2.33.1
v2.33.0
v2.32.1
v2.32.0
v2.31.0
v2.30.0
v2.29.0
v2.28.0
v2.27.0
v2.26.3
v2.26.2
v2.26.1
v2.26.0
v2.25.1
v2.25.0
v2.24.0
v2.23.0
v2.22.0
v2.21.0
v2.20.0
v2.19.5
v2.19.4
v2.19.3
v2.19.2
v2.19.1
v2.19.0
v2.18.1
v2.18.0
v2.17.7
v2.17.6
v2.17.5
v2.17.4
v2.17.3
v2.17.2
v2.17.1
v2.17.0
v2.16.2
v2.16.1
v2.16.0
v2.15.1
v2.15.0
v2.14.0
v2.13.4
v2.13.3
v2.13.2
v2.13.1
v2.13.0
v2.12.3
v2.12.2
v2.12.1
v2.12.0
v2.11.0
v2.10.1
v2.10.0
v2.9.0
v2.8.1
v2.8.0
v2.7.2
v2.7.1
v2.7.0
v2.6.0
v2.5.0
v2.4.4
v2.4.3
v2.4.2
v2.4.1
v2.4.0
v2.3.5
v2.3.4
v2.3.3
v2.3.2
v2.3.1
v2.3.0
v2.2.23
v2.2.22
v2.2.21
v2.2.20
v2.2.19
v2.2.18
v2.2.17
v2.2.16
v2.2.15
v2.2.14
v2.2.13
v2.2.12
v2.2.11
v2.2.10
v2.2.9
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.5
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.24
v2.0.23
v2.0.22
v2.0.21
v2.0.20
v2.0.19
v2.0.18
v2.0.17
v2.0.16
v2.0.15
v2.0.14
v2.0.13
v2.0.12
v2.0.11
v2.0.10
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v1.7.2
v1.7.1
v1.7.0
v1.6.0
v1.5.5
v1.5.0
v1.4.11
v1.4.9
v1.4.7
v1.4.6
v1.4.4
v1.4.2
v1.4.0
v1.4.1
v1.3.4
v1.3.3
v1.3.1
v1.2.8
v1.2.6
v1.2.5
v1.2.4
v1.2.1
v1.1.15
v1.1.14
v1.1.13
v1.1.12
v1.1.11
v1.1.10
v1.1.9
v1.1.8
v1.0.0
0.9.61-beta.0
0.9.61-beta
Labels
Clear labels
authentication
backlog
bug
chapter editor
config-issue
ebooks
encoding/embedding
enhancement
help wanted
listening sessions & progress
planned
possible plugin
progress sync
pull-request
sorting/filtering/searching
unable to reproduce
upload
users & permissions
waiting
Mirrored from GitHub Pull Request
No Label
bug
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
adam (Adam Melkus)
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/audiobookshelf#1598
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Shadow53 on GitHub (Dec 18, 2023).
Describe the issue
I am using a self-hosted Nextcloud server with the OIDC app for logins to other self-hosted services, currently Miniflux and Audiobookshelf. The server is hosted on NixOS, and I am using NixOS packages and configuration for both Nextcloud and Audiobookshelf.
OIDC logins work fine with Miniflux. With Audiobookshelf, I go through the login flow with Nextcloud, then get redirected back to the Audiobookshelf login page with a message "Unauthorized".
I did some digging, and I think the problem is due to openid-client Client's defaults combined with the limitations of the Nextcloud OIDC app. In short, the Nextcloud OIDC app does not support Basic authentication, and that is the default for openid-client.
I believe the fix is to support setting
token_endpoint_auth_methodto either"client_secret_jwt"or"private_key_jwt".Regarding logs:
Dec 17 22:59:02 nixos audiobookshelf[937502]: [2023-12-17 22:59:02.328] DEBUG: [Auth] Set oidc redirect_uri=https://my.audiobookshelf.site/auth/openid/callback (Auth.js:287)Steps to reproduce the issue
Audiobookshelf version
v2.6.0
How are you running audiobookshelf?
Other
@Sapd commented on GitHub (Dec 19, 2023):
You can try the latest
:edgeimage which should give you more detailed logs@Sapd commented on GitHub (Jan 27, 2024):
Can you try this image:
darnst/audiobookshelf:client_secret_postI hardcoded client_secret_post there. If it works I might include it in a PR
@DavidKarlas commented on GitHub (Jun 19, 2025):
FYI: I tried that image and it worked for me with Authelia(I had token_endpoint_auth_method: client_secret_post set in configuration because I copied from elsewhere)
@Vitadek commented on GitHub (Apr 18, 2026):
Since the original ticket is specifically Nextcloud as the oidc provider, I figured I should comment what I did, because I had serious trouble with this. There's a specific use case on why I wanted Nextcloud to be my oidc provider. As setting up an authentik, authelia, or keycloak instance would be a hassle if you only want to extend your Nextcloud auth to one more instance.
I hand jammed a lot of this with Audiobookshelf and the Nextcloud php and used Claude to help me out on some of the manual nextcloud php overrides and sqlite3 manual configurations to force some things through the pipeline. I told it to summarize what I did.
Why Audiobookshelf is Inherently Incompatible with Nextcloud OIDC (Without Workarounds)
Expanding on this issue — after extensive debugging on my own setup, I've confirmed the incompatibility is real and sits at the intersection of two design decisions that each make sense in isolation but collide at the token endpoint.
The Core Conflict
Audiobookshelf uses openid-client (node), which defaults to token_endpoint_auth_method: "client_secret_basic" and doesn't expose a way to override it. Client credentials get sent as Authorization: Basic base64(client_id:client_secret).
Nextcloud core (lib/base.php → handleLogin → tryBasicAuthLogin) intercepts ANY request containing an Authorization: Basic header, regardless of route. It tries to log in the credentials as a Nextcloud user, fails (the client_id isn't a user), and returns 401 — the OIDC app never runs.
The Nextcloud OIDC Identity Provider app (H2CK/oidc) does support client_secret_post, but since openid-client sends both the Basic header AND body params simultaneously, Nextcloud's core interception wins every time.
Why Simple Toggles Would Fix This
Either side adding a boolean config makes the whole problem go away:
Option A — Audiobookshelf side (preferred, cleanest)
Expose token_endpoint_auth_method as a config field. openid-client already supports all the standard values — it's literally one line passed to the Client constructor:
How-To: Get Audiobookshelf OIDC Working with Nextcloud (Workaround)
Since ABS doesn't expose
token_endpoint_auth_method, here's what I had to do to make it work. This involves modifying Nextcloud core, Apache, and nginx. Use at your own risk — the Nextcloud core patch will be overwritten on updates.Environment Tested
nextcloud:33-apache(Docker container nameddocker-app-1)user_oidc)Step 1 — Install the OIDC Identity Provider App
In Nextcloud admin: Apps → search "OpenID Connect" → install the one by H2CK. Confirm:
Step 2 — Create the OIDC Client
Use opaque tokens. JWT tokens in this app version cause
Could not find provided bearer tokenat the userinfo endpoint.If ABS is served from a subpath (e.g.,
/audiobookshelf), add that redirect URI too:Step 3 — Patch Nextcloud Core (
lib/base.php)This is the critical fix. It tells Nextcloud core to skip Basic auth interception on the OIDC token and userinfo endpoints.
Find the line (~1242):
You're looking for:
Apply the patch:
Verify:
The line should now read:
Step 4 — Apache: Enable
CGIPassAuthApache strips the Authorization header from PHP's
$_SERVERby default. The OIDC app's userinfo endpoint needs it for the Bearer token.Step 5 — nginx: Remove Duplicate Authorization Headers
If you have
proxy_pass_request_headers on;ANDproxy_set_header Authorization $http_authorization;in the same block, you get duplicateAuthorizationheaders, which Apache/PHP can't parse correctly.Check current config:
Fix: Remove all explicit Authorization header lines. nginx passes the client's Authorization header through automatically.
Final nginx server block should look like this for the Nextcloud host:
Do NOT add:
proxy_set_header Authorization $http_authorization;proxy_pass_header Authorization;proxy_pass_request_headers on;Reload nginx:
Step 6 — Audiobookshelf Configuration
In ABS: Settings → Authentication → check "OpenID Connect Authentication".
Set Issuer URL to
https://cloud.yourdomain.comand click Auto-populate. All URLs should fill in. Then set:occ oidc:createocc oidc:createRS256username← this is the important one if you want SSO to map to existing local ABS accounts/audiobookshelfif ABS is behind a subpath, otherwise blankMapping OIDC logins to existing ABS users (no duplicate accounts)
With "Match existing users by" set to
username, thepreferred_usernameclaim from Nextcloud will match against your existing ABS username. The user logs in via Nextcloud, gets forwarded to their existing ABS account — no new account created, same permissions and history as their local login. Leave "Auto Register" off to prevent accidental account creation on username mismatches.Step 7 — Test
Reset the brute force throttle (in case you've accumulated failed attempts):
Click the login button in ABS. You should get redirected to Nextcloud, log in, and get sent back to ABS logged in as your existing user.
If it fails, watch:
and
How to Verify Each Step Worked
Login failed: 'CLIENT_ID'in Nextcloud log, token endpoint returns 401 with 14-byte bodyNo bearer token foundCould not find provided bearer tokendespite Bearer header presentOPError: expected 200 OK, got: 401 Unauthorizedin ABS logsOPError: invalid_client (Client authentication failed.)in ABS logsThis entire workaround is only necessary because ABS doesn't expose
token_endpoint_auth_method. Proper upstream fix to ABS would reduce this whole guide to a single config field.Ironically, the duct tape workaround took more time than it would be setting up authelia or authentik. But it's about the principle lol
@Sapd commented on GitHub (Apr 18, 2026):
It is quite easy to fix. I can do so after https://github.com/advplyr/audiobookshelf/pull/5031 is merged. But this will take a while bc of the react rewrite afaik.