mirror of
https://github.com/advplyr/audiobookshelf.git
synced 2026-05-30 23:40:40 +02:00
[Bug]: OIDC via Keycloak not working #2525
Closed
opened 2026-04-25 00:08:02 +02:00 by adam
·
5 comments
No Branch/Tag Specified
master
book_tags_genres_dedupe
episode_download_fallback
Issue-4540-SortBy-StartedDate-and-FinishedDate
episode_meta_tagging
fix_authorize_race_condition
redirect_transcode_requests
progress_updated_sort
fix_ereader_socket_event
fix_change_empty_root_password
fix_podcast_session_track_index
fix_set_token
session_modal_user
localize_durations
fix_oidc_create_user
jwt_auth_refactor
fix_scanner_deleting_single_file_books
fix_mediaprogress_updatedat_2
experimental_next_client
podcast_episode_duration
episode-timestamps-clickable
book_author_secondary_sort_title
podcast_useragents
pathexists_user_access
fix_pathexists_join
book_author_secondary_sort
clean_duplicate_mediaprogress
sanitize_html_description
trix_prevent_attachments
check_path_api_fix
fix_mediaprogress_updatedat
increase_express_json_limit
fix_dockerfile_nunicode
search_episodes
audiobook_tools_update
episode_secondary_sorts
hls_stream_url_update
new_session_track_endpoint
audiobook_tools_enhancements
watcher_rescans_update
player_track_tooltip
fix_exclude_prefixes_crash
socket_item_events
fix_podcast_episode_scanner_promise
new_stats_controller
count_cache_for_userpermissions
parsing-opf-v3
validate_migration_files
fix-quick-match-all-crash
fix-chapter-end-sleep-timer
stringify_sequelize_query
remove-col-ambiguity
fix_next_prev_edit_description
details_trim_whitespace
fix_content_url_basepath
fix_logger_fatal
progress_bar_visibility
batch-edit-populate-map-details
feed_generator_updates
bookmark-modal-updates
migrate-library-item-in-scanner
migrate-new-library-items
migrate-podcasts-new-library-item-2
migrate-podcasts-new-library-item
fix-remove-episode-from-playlist
playback-session-use-new-library-item
refactor-library-item
fix-heatmap-caption
feed-episodes-upsert
share-media-player-media-session-api
remove-old-playlist
remove_old_collection_object
plugin-implementation-demo
feed_migration
refactor-feeds-from-item
fix_remove_authors_no_books
v2.17.3-fk-constraints-migration
migrations-first-upgrade
sqlite_2
feature/nuxt-target-server
waveform
sqlite
playlists
video
v2.35.1
v2.35.0
v2.34.0
v2.33.2
v2.33.1
v2.33.0
v2.32.1
v2.32.0
v2.31.0
v2.30.0
v2.29.0
v2.28.0
v2.27.0
v2.26.3
v2.26.2
v2.26.1
v2.26.0
v2.25.1
v2.25.0
v2.24.0
v2.23.0
v2.22.0
v2.21.0
v2.20.0
v2.19.5
v2.19.4
v2.19.3
v2.19.2
v2.19.1
v2.19.0
v2.18.1
v2.18.0
v2.17.7
v2.17.6
v2.17.5
v2.17.4
v2.17.3
v2.17.2
v2.17.1
v2.17.0
v2.16.2
v2.16.1
v2.16.0
v2.15.1
v2.15.0
v2.14.0
v2.13.4
v2.13.3
v2.13.2
v2.13.1
v2.13.0
v2.12.3
v2.12.2
v2.12.1
v2.12.0
v2.11.0
v2.10.1
v2.10.0
v2.9.0
v2.8.1
v2.8.0
v2.7.2
v2.7.1
v2.7.0
v2.6.0
v2.5.0
v2.4.4
v2.4.3
v2.4.2
v2.4.1
v2.4.0
v2.3.5
v2.3.4
v2.3.3
v2.3.2
v2.3.1
v2.3.0
v2.2.23
v2.2.22
v2.2.21
v2.2.20
v2.2.19
v2.2.18
v2.2.17
v2.2.16
v2.2.15
v2.2.14
v2.2.13
v2.2.12
v2.2.11
v2.2.10
v2.2.9
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.5
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.24
v2.0.23
v2.0.22
v2.0.21
v2.0.20
v2.0.19
v2.0.18
v2.0.17
v2.0.16
v2.0.15
v2.0.14
v2.0.13
v2.0.12
v2.0.11
v2.0.10
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v1.7.2
v1.7.1
v1.7.0
v1.6.0
v1.5.5
v1.5.0
v1.4.11
v1.4.9
v1.4.7
v1.4.6
v1.4.4
v1.4.2
v1.4.0
v1.4.1
v1.3.4
v1.3.3
v1.3.1
v1.2.8
v1.2.6
v1.2.5
v1.2.4
v1.2.1
v1.1.15
v1.1.14
v1.1.13
v1.1.12
v1.1.11
v1.1.10
v1.1.9
v1.1.8
v1.0.0
0.9.61-beta.0
0.9.61-beta
Labels
Clear labels
authentication
backlog
bug
chapter editor
config-issue
ebooks
encoding/embedding
enhancement
help wanted
listening sessions & progress
planned
possible plugin
progress sync
pull-request
sorting/filtering/searching
unable to reproduce
upload
users & permissions
waiting
Mirrored from GitHub Pull Request
No Label
bug
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
adam (Adam Melkus)
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/audiobookshelf#2525
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @blknight88 on GitHub (Jan 26, 2025).
What happened?
I tried to setup OIDC with Keycloak and I cannot get it to work.
Following the provided guide, I added my Issuer URL and auto populated the values in Audiobookshelf in the Authentication section and provided the Client ID/Secret from Keycloak.
In Keycloak I set it to use a Confidential client access type and set the Redirect urls as described in the documentation.
https://www.audiobookshelf.org/guides/oidc_authentication
However when I try to login I get "Error in callback" and looking at the logs section in Audiobookshelf, I see the following error:
[Auth] Error in openid callback - SyntaxError: Unexpected token 'e', \"eyJhbGciOi\"... is not valid JSONLooking at the "Configuring your OIDC provider" of the guide, the only area that looks to be an issue is, "UserInfo Signing Algorithm: Must be set to none/unsigned" as I am running Keycloak 26.0.8 and there is no option to set this to "none."
I already tried asking for help in Discord and after months of no responses I figured I would try here.
I also tried ChatGPT's suggestions to get around the "UserInfo Signing Algorithm: Must be set to none/unsigned" by setting Mappers on this client in Keycloak however that gives me a new error:
"[Auth] No data in openid callback - OPError: unknown_error (For more on this error consult the server log.)"What did you expect to happen?
I expected the login to work via Keycloak.
Steps to reproduce the issue
Audiobookshelf version
2.17.7
How are you running audiobookshelf?
Debian/PPA
What OS is your Audiobookshelf server hosted from?
Linux
If the issue is being seen in the UI, what browsers are you seeing the problem on?
Firefox
Logs
Additional Notes
No response
@HansenRene commented on GitHub (Feb 1, 2025):
I was initially worried about getting my ABS playing with keycloak after reading this Issue. However, it worked on my first attempt, which says a lot as im a novice at IDP.
steps i took in keycloak:
created new client
General settings:
Access settings:
Under Capability config:
and copied the client secret of course, and that was all for the keycloak side
in audiobookshelf I enabled OpenID Connect, entered the issuer url from keycloak and hit the auto populate button.
(something like https://myidp.mydomain.org/realms/myrealm/.well-known/openid-configuration)
As mentioned, I only just started playing with idp's, but ABS implementation of oidc looked alot like the one for mealie, so I basically made the config identical to that one.
hope it helps
@blknight88 commented on GitHub (Feb 2, 2025):
hey @PorreKaj,
Thank you for sharing your experience on how you got yours working.
After deleting my Client from Keycloak to start over, I was able to get it working by following your instructions!
A suggestion for you, using "*" is great for troubleshooting, but is a security risk and thankfully by using the suggested values from the audiobbookshelf guide, I was able to get that working by using the following for my "Valid redirect URIs" in Keycloak:
https://www.audiobookshelf.org/guides/oidc_authentication/
Also I did not need to enable "authorization" either so not sure that is needed.
I think the issue for me was changing "Match existing users by" to "email" instead of "username," even though with this change logging in via username via Keycloak still works. Also Disabling "Auto Register" which I had enabled previously.
The only issue I have now is I can't figure out what the "Valid post logout redirect URIs" is supposed to be. It works if it is set to "https://myaudiobookshelf.mydomain.org/*" however this would be a security risk.
@advplyr commented on GitHub (Feb 2, 2025):
Is there a bug with Abs?
@blknight88 commented on GitHub (Feb 2, 2025):
@advplyr this is not a bug, I thought it might be, but not anymore, I will close this after this comment.
For anyone else watching this, I did figure out the "Valid post logout redirect URIs" setting, this probably should be added to the documentation, but if you want to set it up without using the insecure wildcard "*" you just need to use "/audiobookshelf/login"
@ovizii commented on GitHub (Sep 15, 2025):
This really needs to go into the documentation. I just googled for an hour trying to fix this weird behaviour until I found this tread.