mirror of
https://github.com/advplyr/audiobookshelf.git
synced 2026-05-30 23:40:40 +02:00
Open
opened 2026-04-25 00:19:36 +02:00 by adam
·
0 comments
No Branch/Tag Specified
master
book_tags_genres_dedupe
episode_download_fallback
Issue-4540-SortBy-StartedDate-and-FinishedDate
episode_meta_tagging
fix_authorize_race_condition
redirect_transcode_requests
progress_updated_sort
fix_ereader_socket_event
fix_change_empty_root_password
fix_podcast_session_track_index
fix_set_token
session_modal_user
localize_durations
fix_oidc_create_user
jwt_auth_refactor
fix_scanner_deleting_single_file_books
fix_mediaprogress_updatedat_2
experimental_next_client
podcast_episode_duration
episode-timestamps-clickable
book_author_secondary_sort_title
podcast_useragents
pathexists_user_access
fix_pathexists_join
book_author_secondary_sort
clean_duplicate_mediaprogress
sanitize_html_description
trix_prevent_attachments
check_path_api_fix
fix_mediaprogress_updatedat
increase_express_json_limit
fix_dockerfile_nunicode
search_episodes
audiobook_tools_update
episode_secondary_sorts
hls_stream_url_update
new_session_track_endpoint
audiobook_tools_enhancements
watcher_rescans_update
player_track_tooltip
fix_exclude_prefixes_crash
socket_item_events
fix_podcast_episode_scanner_promise
new_stats_controller
count_cache_for_userpermissions
parsing-opf-v3
validate_migration_files
fix-quick-match-all-crash
fix-chapter-end-sleep-timer
stringify_sequelize_query
remove-col-ambiguity
fix_next_prev_edit_description
details_trim_whitespace
fix_content_url_basepath
fix_logger_fatal
progress_bar_visibility
batch-edit-populate-map-details
feed_generator_updates
bookmark-modal-updates
migrate-library-item-in-scanner
migrate-new-library-items
migrate-podcasts-new-library-item-2
migrate-podcasts-new-library-item
fix-remove-episode-from-playlist
playback-session-use-new-library-item
refactor-library-item
fix-heatmap-caption
feed-episodes-upsert
share-media-player-media-session-api
remove-old-playlist
remove_old_collection_object
plugin-implementation-demo
feed_migration
refactor-feeds-from-item
fix_remove_authors_no_books
v2.17.3-fk-constraints-migration
migrations-first-upgrade
sqlite_2
feature/nuxt-target-server
waveform
sqlite
playlists
video
v2.35.1
v2.35.0
v2.34.0
v2.33.2
v2.33.1
v2.33.0
v2.32.1
v2.32.0
v2.31.0
v2.30.0
v2.29.0
v2.28.0
v2.27.0
v2.26.3
v2.26.2
v2.26.1
v2.26.0
v2.25.1
v2.25.0
v2.24.0
v2.23.0
v2.22.0
v2.21.0
v2.20.0
v2.19.5
v2.19.4
v2.19.3
v2.19.2
v2.19.1
v2.19.0
v2.18.1
v2.18.0
v2.17.7
v2.17.6
v2.17.5
v2.17.4
v2.17.3
v2.17.2
v2.17.1
v2.17.0
v2.16.2
v2.16.1
v2.16.0
v2.15.1
v2.15.0
v2.14.0
v2.13.4
v2.13.3
v2.13.2
v2.13.1
v2.13.0
v2.12.3
v2.12.2
v2.12.1
v2.12.0
v2.11.0
v2.10.1
v2.10.0
v2.9.0
v2.8.1
v2.8.0
v2.7.2
v2.7.1
v2.7.0
v2.6.0
v2.5.0
v2.4.4
v2.4.3
v2.4.2
v2.4.1
v2.4.0
v2.3.5
v2.3.4
v2.3.3
v2.3.2
v2.3.1
v2.3.0
v2.2.23
v2.2.22
v2.2.21
v2.2.20
v2.2.19
v2.2.18
v2.2.17
v2.2.16
v2.2.15
v2.2.14
v2.2.13
v2.2.12
v2.2.11
v2.2.10
v2.2.9
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.5
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.24
v2.0.23
v2.0.22
v2.0.21
v2.0.20
v2.0.19
v2.0.18
v2.0.17
v2.0.16
v2.0.15
v2.0.14
v2.0.13
v2.0.12
v2.0.11
v2.0.10
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v1.7.2
v1.7.1
v1.7.0
v1.6.0
v1.5.5
v1.5.0
v1.4.11
v1.4.9
v1.4.7
v1.4.6
v1.4.4
v1.4.2
v1.4.0
v1.4.1
v1.3.4
v1.3.3
v1.3.1
v1.2.8
v1.2.6
v1.2.5
v1.2.4
v1.2.1
v1.1.15
v1.1.14
v1.1.13
v1.1.12
v1.1.11
v1.1.10
v1.1.9
v1.1.8
v1.0.0
0.9.61-beta.0
0.9.61-beta
Labels
Clear labels
authentication
backlog
bug
chapter editor
config-issue
ebooks
encoding/embedding
enhancement
help wanted
listening sessions & progress
planned
possible plugin
progress sync
pull-request
sorting/filtering/searching
unable to reproduce
upload
users & permissions
waiting
Mirrored from GitHub Pull Request
No Label
pull-request
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
adam (Adam Melkus)
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/audiobookshelf#4399
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/advplyr/audiobookshelf/pull/5031
Author: @Sapd
Created: 2/5/2026
Status: 🔄 Open
Base:
master← Head:oidc-revamp📝 Commits (10+)
33bee70Revamp OIDC auth: remove Passport wrapper, add schema-driven settings UI073eff7Add OIDC Back-Channel Logout supported0db53Add unit tests for 5 OidcAuthStrategy methodsd504797Add unit tests for OIDC callback flow and authorizationb3d63f4Fix backchannel logout always returning 50149aeb2dRequire email_verified to be explicitly true when enforcement is enabledc2a7615OIDC: Improve error messagese428ba5OIDC: Fix CodeQL warningsc99543bUpdate en-us.json84b3d4dFix migration crash on upgrade from v2.31.0📊 Changes
22 files changed (+3370 additions, -580 deletions)
View changed files
➕
client/components/app/KeyValueEditor.vue(+97 -0)➕
client/components/app/OidcSettings.vue(+126 -0)📝
client/layouts/default.vue(+11 -0)📝
client/pages/config/authentication.vue(+91 -254)📝
client/strings/en-us.json(+1 -0)📝
package.json(+2 -1)📝
server/Auth.js(+127 -159)➕
server/auth/AuthError.js(+9 -0)➕
server/auth/BackchannelLogoutHandler.js(+148 -0)📝
server/auth/OidcAuthStrategy.js(+202 -96)➕
server/auth/OidcSettingsSchema.js(+348 -0)📝
server/auth/TokenManager.js(+15 -2)📝
server/controllers/MiscController.js(+125 -55)➕
server/migrations/v2.33.0-oidc-scopes-and-group-map.js(+143 -0)➕
server/migrations/v2.34.0-backchannel-logout.js(+127 -0)📝
server/models/Session.js(+9 -3)📝
server/objects/settings/ServerSettings.js(+38 -10)📝
server/routers/ApiRouter.js(+1 -0)➕
test/server/auth/AuthError.test.js(+24 -0)➕
test/server/auth/BackchannelLogoutHandler.test.js(+319 -0)...and 2 more files
📄 Description
This PR revamps the OIDC system. Passport is removed. Support for groups mapping provided, and scopes can now be configured.
In-depth Description
Passport was removed for OIDC
It clashed how we OIDC used. We are not only an OIDC relying party but also an OAuth2 proxy for mobile clients. Thats a use case the passport provider does not handle well, we did some hacks before to support that. The new code is much simpler
Add Server-Driven (or also called Schema-Driven) UI for the OIDC settings
Instead of defining the settings (again) in the frontend, the server provides a schema and the frontend automatically renders all settings. Minimizes code (less duplication) and bugs. I would also recommend that for all other settings, however I handled here only OIDC.
OIDC Mappings
Added group mappings. A group from the identity provider can be now directly mapped to a ABS group. Also scopes can now be configured. Fixes #2878 and Fixes #3006
Fixed also some edge cases of validation (Fixes #4744 )
Add verified email enforcement option
Every idP provider handles the email_verified field differently (some provide hardcoded true or false or do not provide it). The Admin can now configure how ABS should handle the field. Fixes #4832
If the setting is turned on, it is expected that the IdP sends the value with and that its true.
Store OIDCToken in session table instead of cookie
The token is better placed server side. Also it can be quite long exceeding maximum allowed cookies length.
Add Back-Channel Logout support
Authentik now supports Back-Channel logout. So I implemented it here, too.
There is a POST endpoint on ABS side. When the configuration is turned on, it accepts a signed JWT from Authentik and can cancel sessions.
When a user logs out on Authentik, Authentik will use it to log out a user on ABS too. (The user's existing access token remains valid until it expires).
Other
Jose was added as explicit dependency for Backchannel Logout (there for checking the JWT). It was a dependency anyway from node-openid-client.
How have you tested this?
Simply add a mapper for one on the groups and use as value an Authentik Group.
For Backchannel logout. Make sure to configure the URL in Authentik. Then check the sessions in ABS sqliteDB. Then log out in authentik. You should see in the ABS Console a message that there was a Back Channel logout. The session will be gone in the ABS sqliteDB.
Also added extensive unit tests.
Screenshots
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.