Fix Authelia OIDC: send state (+ remove login redirect hint) (#9)

Auth.js OIDC defaults to PKCE-only, so no `state` was sent; Authelia
rejects that. Enable checks: pkce + state. Remove the public redirect
URI hint from the login page.

Co-authored-by: Cursor Agent <[email protected]>
This commit is contained in:
Nick Trochalakis
2026-08-24 04:19:29 +00:00
committed by GitHub
co-authored by Cursor Agent
parent 443dba5bba
commit c33f651cfe
3 changed files with 10 additions and 24 deletions
-6
View File
@@ -6,16 +6,10 @@ import { LoginPageClient } from "@/components/LoginPageClient";
export const dynamic = "force-dynamic"; export const dynamic = "force-dynamic";
export default function LoginPage() { export default function LoginPage() {
const authUrl = (process.env.AUTH_URL || "").replace(/\/$/, "");
const callbackUrlHint = authUrl
? `${authUrl}/api/auth/callback/oidc`
: "https://<your-host>/api/auth/callback/oidc";
return ( return (
<LoginPageClient <LoginPageClient
oidcEnabled={isOidcConfigured()} oidcEnabled={isOidcConfigured()}
oidcName={process.env.AUTH_OIDC_NAME || "SSO"} oidcName={process.env.AUTH_OIDC_NAME || "SSO"}
callbackUrlHint={callbackUrlHint}
/> />
); );
} }
+8 -18
View File
@@ -8,13 +8,11 @@ import { Suspense } from "react";
type Props = { type Props = {
oidcEnabled: boolean; oidcEnabled: boolean;
oidcName: string; oidcName: string;
callbackUrlHint: string;
}; };
type AuthConfig = { type AuthConfig = {
oidcEnabled: boolean; oidcEnabled: boolean;
oidcName: string; oidcName: string;
callbackUrl: string;
}; };
function authErrorMessage(code: string | null): string | null { function authErrorMessage(code: string | null): string | null {
@@ -36,7 +34,7 @@ function authErrorMessage(code: string | null): string | null {
} }
} }
function LoginForm({ oidcEnabled, oidcName, callbackUrlHint }: Props) { function LoginForm({ oidcEnabled, oidcName }: Props) {
const router = useRouter(); const router = useRouter();
const params = useSearchParams(); const params = useSearchParams();
const callbackUrl = params.get("callbackUrl") || "/"; const callbackUrl = params.get("callbackUrl") || "/";
@@ -62,7 +60,6 @@ function LoginForm({ oidcEnabled, oidcName, callbackUrlHint }: Props) {
const showOidc = runtimeOidc?.oidcEnabled ?? oidcEnabled; const showOidc = runtimeOidc?.oidcEnabled ?? oidcEnabled;
const displayName = runtimeOidc?.oidcName || oidcName; const displayName = runtimeOidc?.oidcName || oidcName;
const redirectHint = runtimeOidc?.callbackUrl || callbackUrlHint;
async function onSubmit(e: FormEvent) { async function onSubmit(e: FormEvent) {
e.preventDefault(); e.preventDefault();
@@ -121,20 +118,13 @@ function LoginForm({ oidcEnabled, oidcName, callbackUrlHint }: Props) {
{loading ? "Signing in…" : "Sign in"} {loading ? "Signing in…" : "Sign in"}
</button> </button>
{showOidc && ( {showOidc && (
<> <button
<button type="button"
type="button" className="btn btn-secondary"
className="btn btn-secondary" onClick={() => signIn("oidc", { callbackUrl })}
onClick={() => signIn("oidc", { callbackUrl })} >
> Sign in with {displayName}
Sign in with {displayName} </button>
</button>
<p className="muted" style={{ margin: 0, fontSize: "0.75rem" }}>
IdP redirect URI must be exactly:
<br />
<code className="mono">{redirectHint}</code>
</p>
</>
)} )}
</form> </form>
</div> </div>
+2
View File
@@ -45,6 +45,8 @@ function buildProviders(): Provider[] {
wellKnown: `${issuer}/.well-known/openid-configuration`, wellKnown: `${issuer}/.well-known/openid-configuration`,
clientId: process.env.AUTH_OIDC_CLIENT_ID!, clientId: process.env.AUTH_OIDC_CLIENT_ID!,
clientSecret: process.env.AUTH_OIDC_CLIENT_SECRET!, clientSecret: process.env.AUTH_OIDC_CLIENT_SECRET!,
// Auth.js OIDC defaults to PKCE-only; Authelia requires a strong `state`
checks: ["pkce", "state"],
authorization: { authorization: {
params: { params: {
scope: "openid email profile", scope: "openid email profile",