mirror of
https://github.com/advplyr/audiobookshelf.git
synced 2026-07-31 17:08:41 +02:00
[Bug]: Error: "[OidcAuth] openid callback error: Invalid userinfo or already linked Error: Invalid userinfo or already linked at OidcAuthStrategy.verifyCallback (/app/server/auth/OidcAuthStrategy.js:129:15)" when attempting to add/match new user #3069
Closed
opened 2026-04-25 00:13:24 +02:00 by adam
·
7 comments
No Branch/Tag Specified
master
auth_sessions_enhancements
account_sessions_table
logout_all_devices
pw_change_invalidates_sessions
book_tags_genres_dedupe
episode_download_fallback
Issue-4540-SortBy-StartedDate-and-FinishedDate
episode_meta_tagging
fix_authorize_race_condition
redirect_transcode_requests
progress_updated_sort
fix_ereader_socket_event
fix_change_empty_root_password
fix_podcast_session_track_index
fix_set_token
session_modal_user
localize_durations
fix_oidc_create_user
jwt_auth_refactor
fix_scanner_deleting_single_file_books
fix_mediaprogress_updatedat_2
experimental_next_client
podcast_episode_duration
episode-timestamps-clickable
book_author_secondary_sort_title
podcast_useragents
pathexists_user_access
fix_pathexists_join
book_author_secondary_sort
clean_duplicate_mediaprogress
sanitize_html_description
trix_prevent_attachments
check_path_api_fix
fix_mediaprogress_updatedat
increase_express_json_limit
fix_dockerfile_nunicode
search_episodes
audiobook_tools_update
episode_secondary_sorts
hls_stream_url_update
new_session_track_endpoint
audiobook_tools_enhancements
watcher_rescans_update
player_track_tooltip
fix_exclude_prefixes_crash
socket_item_events
fix_podcast_episode_scanner_promise
new_stats_controller
count_cache_for_userpermissions
parsing-opf-v3
validate_migration_files
fix-quick-match-all-crash
fix-chapter-end-sleep-timer
stringify_sequelize_query
remove-col-ambiguity
fix_next_prev_edit_description
details_trim_whitespace
fix_content_url_basepath
fix_logger_fatal
progress_bar_visibility
batch-edit-populate-map-details
feed_generator_updates
bookmark-modal-updates
migrate-library-item-in-scanner
migrate-new-library-items
migrate-podcasts-new-library-item-2
migrate-podcasts-new-library-item
fix-remove-episode-from-playlist
playback-session-use-new-library-item
refactor-library-item
fix-heatmap-caption
feed-episodes-upsert
share-media-player-media-session-api
remove-old-playlist
remove_old_collection_object
plugin-implementation-demo
feed_migration
refactor-feeds-from-item
fix_remove_authors_no_books
v2.17.3-fk-constraints-migration
migrations-first-upgrade
sqlite_2
feature/nuxt-target-server
waveform
sqlite
playlists
video
v2.36.0
v2.35.1
v2.35.0
v2.34.0
v2.33.2
v2.33.1
v2.33.0
v2.32.1
v2.32.0
v2.31.0
v2.30.0
v2.29.0
v2.28.0
v2.27.0
v2.26.3
v2.26.2
v2.26.1
v2.26.0
v2.25.1
v2.25.0
v2.24.0
v2.23.0
v2.22.0
v2.21.0
v2.20.0
v2.19.5
v2.19.4
v2.19.3
v2.19.2
v2.19.1
v2.19.0
v2.18.1
v2.18.0
v2.17.7
v2.17.6
v2.17.5
v2.17.4
v2.17.3
v2.17.2
v2.17.1
v2.17.0
v2.16.2
v2.16.1
v2.16.0
v2.15.1
v2.15.0
v2.14.0
v2.13.4
v2.13.3
v2.13.2
v2.13.1
v2.13.0
v2.12.3
v2.12.2
v2.12.1
v2.12.0
v2.11.0
v2.10.1
v2.10.0
v2.9.0
v2.8.1
v2.8.0
v2.7.2
v2.7.1
v2.7.0
v2.6.0
v2.5.0
v2.4.4
v2.4.3
v2.4.2
v2.4.1
v2.4.0
v2.3.5
v2.3.4
v2.3.3
v2.3.2
v2.3.1
v2.3.0
v2.2.23
v2.2.22
v2.2.21
v2.2.20
v2.2.19
v2.2.18
v2.2.17
v2.2.16
v2.2.15
v2.2.14
v2.2.13
v2.2.12
v2.2.11
v2.2.10
v2.2.9
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.5
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.24
v2.0.23
v2.0.22
v2.0.21
v2.0.20
v2.0.19
v2.0.18
v2.0.17
v2.0.16
v2.0.15
v2.0.14
v2.0.13
v2.0.12
v2.0.11
v2.0.10
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v1.7.2
v1.7.1
v1.7.0
v1.6.0
v1.5.5
v1.5.0
v1.4.11
v1.4.9
v1.4.7
v1.4.6
v1.4.4
v1.4.2
v1.4.0
v1.4.1
v1.3.4
v1.3.3
v1.3.1
v1.2.8
v1.2.6
v1.2.5
v1.2.4
v1.2.1
v1.1.15
v1.1.14
v1.1.13
v1.1.12
v1.1.11
v1.1.10
v1.1.9
v1.1.8
v1.0.0
0.9.61-beta.0
0.9.61-beta
Labels
Clear labels
authentication
backlog
bug
chapter editor
config-issue
ebooks
encoding/embedding
enhancement
help wanted
listening sessions & progress
planned
possible plugin
progress sync
pull-request
sorting/filtering/searching
unable to reproduce
upload
users & permissions
waiting
Mirrored from GitHub Pull Request
No labels
bug
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Assignees
adam (Adam Melkus)
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/audiobookshelf#3069
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @ZLoth on GitHub (Nov 3, 2025).
What happened?
I'm running into an issue with creating two users on my ABS instance using Authentik as my provider. Logins work fine.
Troubleshooting steps that I have tried:
I should note that I was able to successfully create accounts and login to Kavita for these two users.
The configuration is as follows:
I am running this on a TrueNAS 25.10 server which is running on Debian Linux.
Configuration for ABS:
From Authentik:
Redirect URIs:
What did you expect to happen?
User that was created in the Authetik application should have been created in ABS. Failing that, user should have been matched.
Steps to reproduce the issue
WHAT SHOULD HAPPEN: User is created or authenticated.
WHAT REALLY HAPPENS: Error message "Unauthorized"
Audiobookshelf version
2.30
How are you running audiobookshelf?
Docker
What OS is your Audiobookshelf server hosted from?
Linux
If the issue is being seen in the UI, what browsers are you seeing the problem on?
Chrome
Logs
Both log excerpts are from Audobookshelf .
Additional Notes
@ZLoth commented on GitHub (Nov 4, 2025):
Authentik upgraded to 2025.10.1 today, but issue is still occurring.
@Vito0912 commented on GitHub (Nov 4, 2025):
This very likely is related to
https://github.com/goauthentik/authentik/pull/16206/and is in general (even if not) unlikley an ABS bug due to receiving the data from the OIDC provider@ZLoth commented on GitHub (Nov 4, 2025):
Okay.... so I looking quickly at the JWT payload and see the following:
The
"email_verified": falseis causing a failure in Audiobookshelf. When I go into Authentik → Customization → Property Mappings → authentik default OAuth Mapping: OpenID 'email' , I see the following in Expression:Because it is hard-coded to be False instead of being mapped to a variable, it is causing issues. Creating a new scope and settings
"email_verified": Truefixed the issue.This issue has been documented in the release notes as https://docs.goauthentik.io/releases/2025.10#default-oauth-scope-mappings as part of the release on October 21st.
@ZLoth commented on GitHub (Nov 4, 2025):
This may need to be integrated to https://www.audiobookshelf.org/guides/oidc_authentication .
Steps to fix this
"email_verified": falsefor Audiobookshelf:Name:
OAuth Mapping: OpenID 'email' with "email_verified": TrueScope Name:
emailDescription:
Email addressExpression:
Provider for Audiobookshelf.authentik default OAuth Mapping: OpenID 'email'and click on the left arrow to remove it from the Selected Scopes list.OAuth Mapping: OpenID 'email' with "email_verified": Trueand click on the right arrow to add it to the Selected Scopes list.authentik default OAuth Mapping: OpenID 'openid'andauthentik default OAuth Mapping: OpenID 'profile'are still in the Selected Scopes list."email_verified": trueshould now be returned.@MRobi1 commented on GitHub (Nov 6, 2025):
This didn't quite fix it for me.
I've been using Authentik for quite some time as an OIDC provider for audiobookshelf. I tried to login this morning and was met with the "Unauthorized". I've also disabled password login so navigating to https://abs.yoursite.com/login/?autoLaunch=0 only gives me the option to login via OIDC.
I was getting the same error above. Followed these steps. Now getting this error
So it appears as-if my e-mail is now being passed through, but still cannot log in because that e-mail is already linked to an existing user.
I appear to be fully locked out
@Vito0912 commented on GitHub (Nov 6, 2025):
@MRobi1 If you link your account with an OIDC provider, it sets a unique ID for the user linked to your ABS account (provided by your OIDC provider).
As you can see from the message (you already have linked that account), there are a few possible reasons why this can happen:
A) You reset your Authentik instance, which will then generate a new sub
B) You change the way the sub is generated (e.g. changing the subject mode in Authentik)
C) Possibly something I don't know. Anyway, this also doesn't seem to be an ABS issue but an issue caused by the sub changing.
To recover your account you either have to fix the sub or if you changed something on your Authentik instance irreversible you need to unlink the account
@MRobi1 commented on GitHub (Nov 7, 2025):
OK I'm back in business. Since I had disabled password login, I was fully locked out. Had to manually edit the database to remove all OIDC settings. Then I could log in with my password again. Had to reconfigure OIDC which got me to the same error, but since I was now able to login normally I could unlink OIDC through settings.
Not sure what changed. I hadn't touched the config on either side in around 1yr+