mirror of
https://github.com/advplyr/audiobookshelf.git
synced 2026-05-30 23:40:40 +02:00
[Bug]: OIDC fails with LastLogin.io/Obligator #1820
Closed
opened 2026-04-24 23:59:08 +02:00 by adam
·
10 comments
No Branch/Tag Specified
master
book_tags_genres_dedupe
episode_download_fallback
Issue-4540-SortBy-StartedDate-and-FinishedDate
episode_meta_tagging
fix_authorize_race_condition
redirect_transcode_requests
progress_updated_sort
fix_ereader_socket_event
fix_change_empty_root_password
fix_podcast_session_track_index
fix_set_token
session_modal_user
localize_durations
fix_oidc_create_user
jwt_auth_refactor
fix_scanner_deleting_single_file_books
fix_mediaprogress_updatedat_2
experimental_next_client
podcast_episode_duration
episode-timestamps-clickable
book_author_secondary_sort_title
podcast_useragents
pathexists_user_access
fix_pathexists_join
book_author_secondary_sort
clean_duplicate_mediaprogress
sanitize_html_description
trix_prevent_attachments
check_path_api_fix
fix_mediaprogress_updatedat
increase_express_json_limit
fix_dockerfile_nunicode
search_episodes
audiobook_tools_update
episode_secondary_sorts
hls_stream_url_update
new_session_track_endpoint
audiobook_tools_enhancements
watcher_rescans_update
player_track_tooltip
fix_exclude_prefixes_crash
socket_item_events
fix_podcast_episode_scanner_promise
new_stats_controller
count_cache_for_userpermissions
parsing-opf-v3
validate_migration_files
fix-quick-match-all-crash
fix-chapter-end-sleep-timer
stringify_sequelize_query
remove-col-ambiguity
fix_next_prev_edit_description
details_trim_whitespace
fix_content_url_basepath
fix_logger_fatal
progress_bar_visibility
batch-edit-populate-map-details
feed_generator_updates
bookmark-modal-updates
migrate-library-item-in-scanner
migrate-new-library-items
migrate-podcasts-new-library-item-2
migrate-podcasts-new-library-item
fix-remove-episode-from-playlist
playback-session-use-new-library-item
refactor-library-item
fix-heatmap-caption
feed-episodes-upsert
share-media-player-media-session-api
remove-old-playlist
remove_old_collection_object
plugin-implementation-demo
feed_migration
refactor-feeds-from-item
fix_remove_authors_no_books
v2.17.3-fk-constraints-migration
migrations-first-upgrade
sqlite_2
feature/nuxt-target-server
waveform
sqlite
playlists
video
v2.35.1
v2.35.0
v2.34.0
v2.33.2
v2.33.1
v2.33.0
v2.32.1
v2.32.0
v2.31.0
v2.30.0
v2.29.0
v2.28.0
v2.27.0
v2.26.3
v2.26.2
v2.26.1
v2.26.0
v2.25.1
v2.25.0
v2.24.0
v2.23.0
v2.22.0
v2.21.0
v2.20.0
v2.19.5
v2.19.4
v2.19.3
v2.19.2
v2.19.1
v2.19.0
v2.18.1
v2.18.0
v2.17.7
v2.17.6
v2.17.5
v2.17.4
v2.17.3
v2.17.2
v2.17.1
v2.17.0
v2.16.2
v2.16.1
v2.16.0
v2.15.1
v2.15.0
v2.14.0
v2.13.4
v2.13.3
v2.13.2
v2.13.1
v2.13.0
v2.12.3
v2.12.2
v2.12.1
v2.12.0
v2.11.0
v2.10.1
v2.10.0
v2.9.0
v2.8.1
v2.8.0
v2.7.2
v2.7.1
v2.7.0
v2.6.0
v2.5.0
v2.4.4
v2.4.3
v2.4.2
v2.4.1
v2.4.0
v2.3.5
v2.3.4
v2.3.3
v2.3.2
v2.3.1
v2.3.0
v2.2.23
v2.2.22
v2.2.21
v2.2.20
v2.2.19
v2.2.18
v2.2.17
v2.2.16
v2.2.15
v2.2.14
v2.2.13
v2.2.12
v2.2.11
v2.2.10
v2.2.9
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.5
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.24
v2.0.23
v2.0.22
v2.0.21
v2.0.20
v2.0.19
v2.0.18
v2.0.17
v2.0.16
v2.0.15
v2.0.14
v2.0.13
v2.0.12
v2.0.11
v2.0.10
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v1.7.2
v1.7.1
v1.7.0
v1.6.0
v1.5.5
v1.5.0
v1.4.11
v1.4.9
v1.4.7
v1.4.6
v1.4.4
v1.4.2
v1.4.0
v1.4.1
v1.3.4
v1.3.3
v1.3.1
v1.2.8
v1.2.6
v1.2.5
v1.2.4
v1.2.1
v1.1.15
v1.1.14
v1.1.13
v1.1.12
v1.1.11
v1.1.10
v1.1.9
v1.1.8
v1.0.0
0.9.61-beta.0
0.9.61-beta
Labels
Clear labels
authentication
backlog
bug
chapter editor
config-issue
ebooks
encoding/embedding
enhancement
help wanted
listening sessions & progress
planned
possible plugin
progress sync
pull-request
sorting/filtering/searching
unable to reproduce
upload
users & permissions
waiting
Mirrored from GitHub Pull Request
No Label
bug
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
adam (Adam Melkus)
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/audiobookshelf#1820
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @deanishe on GitHub (Mar 17, 2024).
Describe the issue
SSO doesn't work with LastLogin.io (a public instance of Obligator).
Login fails with the log messages:
I've tried both lastlogin.io and my self-hosted Obligator. I also verified both of those are working correctly with the OpenID Connect Playground.
Steps to reproduce the issue
Audiobookshelf version
v2.8.1
How are you running audiobookshelf?
Docker
@Sapd commented on GitHub (Mar 17, 2024):
I quickly tested it with Lastlogin and it works for me.
Did you use your domains als clientid as their docs say? For example http://example.com
Otherwise can you add here a line
https://github.com/advplyr/audiobookshelf/blob/166454ef43e3cdb42c644cdccdacddd3a880cd89/server/Auth.js#L101
@Sapd commented on GitHub (Mar 29, 2024):
Another follow up question:
How do you match users? Do you create them before? If yes, can you also try with auto-register on?
@deanishe commented on GitHub (Apr 1, 2024):
Yes. Obligator immediately throws an error if the client ID is not okay. It won't redirect back to ABS in that case.
I'm afraid I can't. It's running on a managed server.
@Sapd commented on GitHub (Apr 1, 2024):
Can you swap the docker image simply with
ghcr.io/advplyr/audiobookshelf:edge? It should include better error messages (and it also might directly work bc of some changes).@deanishe commented on GitHub (Apr 1, 2024):
No, I'm afraid not. As I said, it's a managed server. There's an "Update" button I can hit to update the Docker image when a newer release is available, but that's basically all I can do.
@Sapd commented on GitHub (Apr 3, 2024):
I see, you would have to wait until the next release then which includes the changes
@TheJenious0917 commented on GitHub (Apr 14, 2024):
@Sapd - I am experiencing the same issue here. I'm using Microsoft Entra (Azure AD) for OIDC in my case. I switched to the edge release like you suggested.
In the logs I now see my name details returned, but I do not see email fields/claims and the user is "not found" in abs. I have abs set to match based on email, and I do not have Allow Registration enabled simple because I was trying to test out matching up this Entra account with the local one I had created. In the Entra app I added some access/ID token claims to include email and profile information as a troubleshooting step, which did not help.
Here's the log:
Let me know if you need any additional server config info or logs or anything. Was happy to see you guys have SSO support added! Though once we get this issue figured out, I'd love to see if you have any documentation on configuring oidc via environment variables in my compose file...
@TheJenious0917 commented on GitHub (Apr 14, 2024):
Oh, I should add -
I set user matching to "Do not match" and then enabled user registration and my user account was created. Email address or username from the provider are not included in the created user details in ABS that I can tell. Here's the logs for that event.
@TheJenious0917 commented on GitHub (Apr 14, 2024):
Uh, sorry. Another update. I figured out that even though my email address is part of my Microsoft account, the actual identity property of "email" in my contact info was blank and was therefore sending nothing back in the claim. As soon as I filled that in in my Entra user contact info, it worked with user match based on email. So this is solved for me now.
@Sapd commented on GitHub (Apr 22, 2024):
@deanishe You can try again with the latest version