Author SHA1 Message Date
Cursor Agent 88c0c4a453 Fix Authelia OIDC state check and hide redirect URI on login
Auth.js OIDC defaults to PKCE-only, so no `state` was sent; Authelia
rejects that. Enable checks: pkce + state. Remove the public redirect
URI hint from the login page.
2026-08-24 04:12:34 +00:00
3 changed files with 10 additions and 24 deletions
-6
View File
@@ -6,16 +6,10 @@ import { LoginPageClient } from "@/components/LoginPageClient";
export const dynamic = "force-dynamic";
export default function LoginPage() {
const authUrl = (process.env.AUTH_URL || "").replace(/\/$/, "");
const callbackUrlHint = authUrl
? `${authUrl}/api/auth/callback/oidc`
: "https://<your-host>/api/auth/callback/oidc";
return (
<LoginPageClient
oidcEnabled={isOidcConfigured()}
oidcName={process.env.AUTH_OIDC_NAME || "SSO"}
callbackUrlHint={callbackUrlHint}
/>
);
}
+1 -11
View File
@@ -8,13 +8,11 @@ import { Suspense } from "react";
type Props = {
oidcEnabled: boolean;
oidcName: string;
callbackUrlHint: string;
};
type AuthConfig = {
oidcEnabled: boolean;
oidcName: string;
callbackUrl: string;
};
function authErrorMessage(code: string | null): string | null {
@@ -36,7 +34,7 @@ function authErrorMessage(code: string | null): string | null {
}
}
function LoginForm({ oidcEnabled, oidcName, callbackUrlHint }: Props) {
function LoginForm({ oidcEnabled, oidcName }: Props) {
const router = useRouter();
const params = useSearchParams();
const callbackUrl = params.get("callbackUrl") || "/";
@@ -62,7 +60,6 @@ function LoginForm({ oidcEnabled, oidcName, callbackUrlHint }: Props) {
const showOidc = runtimeOidc?.oidcEnabled ?? oidcEnabled;
const displayName = runtimeOidc?.oidcName || oidcName;
const redirectHint = runtimeOidc?.callbackUrl || callbackUrlHint;
async function onSubmit(e: FormEvent) {
e.preventDefault();
@@ -121,7 +118,6 @@ function LoginForm({ oidcEnabled, oidcName, callbackUrlHint }: Props) {
{loading ? "Signing in…" : "Sign in"}
</button>
{showOidc && (
<>
<button
type="button"
className="btn btn-secondary"
@@ -129,12 +125,6 @@ function LoginForm({ oidcEnabled, oidcName, callbackUrlHint }: Props) {
>
Sign in with {displayName}
</button>
<p className="muted" style={{ margin: 0, fontSize: "0.75rem" }}>
IdP redirect URI must be exactly:
<br />
<code className="mono">{redirectHint}</code>
</p>
</>
)}
</form>
</div>
+2
View File
@@ -45,6 +45,8 @@ function buildProviders(): Provider[] {
wellKnown: `${issuer}/.well-known/openid-configuration`,
clientId: process.env.AUTH_OIDC_CLIENT_ID!,
clientSecret: process.env.AUTH_OIDC_CLIENT_SECRET!,
// Auth.js OIDC defaults to PKCE-only; Authelia requires a strong `state`
checks: ["pkce", "state"],
authorization: {
params: {
scope: "openid email profile",