feat: add a master OAuth / OIDC enable toggle in Authentication settings (#26988)

The OAuth / OIDC section in Admin Settings > Authentication had no
enable/disable switch, unlike the LDAP section above it. Add one that
persists via the existing Save flow and actually gates OAuth sign-in,
mirroring how the LDAP toggle works.

- config: new ENABLE_OAUTH persistent config ('oauth.enable'), defaulting
  to True so existing deployments with a provider configured keep working.
- oauth: expose ENABLE_OAUTH via the OAuth runtime config and reject the
  login and callback handlers with 404 when it is disabled.
- /api/config: report no OAuth providers when disabled so the login page
  hides the OAuth buttons (and cannot auto-redirect), without clearing the
  admin's provider configuration.
- auths: expose ENABLE_OAUTH through the admin OAuth config get/update
  endpoints (OAuthConfigForm + OAUTH_CONFIG_KEYS).
- Authentication.svelte: bind the OAuth / OIDC header Switch to the
  persisted oauthConfig.ENABLE_OAUTH and collapse the section when off,
  matching the LDAP header (size, weight, alignment).
This commit is contained in:
G30
2026-07-26 18:43:21 -04:00
committed by GitHub
parent 18ca19044c
commit 71f8b6d5b4
5 changed files with 282 additions and 239 deletions
+6
View File
@@ -35,6 +35,7 @@ from mcp.shared.auth import (
from open_webui.config import (
DEFAULT_USER_ROLE,
ENABLE_OAUTH_GROUP_CREATION,
ENABLE_OAUTH,
ENABLE_OAUTH_GROUP_MANAGEMENT,
ENABLE_OAUTH_ROLE_MANAGEMENT,
ENABLE_OAUTH_SIGNUP,
@@ -120,6 +121,7 @@ OAUTH_RESOURCE_PARAMETER_MODES = {'auto', 'include', 'omit'}
OAUTH_RUNTIME_CONFIG = {
'DEFAULT_USER_ROLE': ('ui.default_user_role', DEFAULT_USER_ROLE),
'ENABLE_OAUTH': ('oauth.enable', ENABLE_OAUTH),
'ENABLE_OAUTH_SIGNUP': ('oauth.enable_signup', ENABLE_OAUTH_SIGNUP),
'OAUTH_REFRESH_TOKEN_INCLUDE_SCOPE': (
'oauth.refresh_token.include_scope',
@@ -1670,6 +1672,8 @@ class OAuthManager:
async def handle_login(self, request, provider):
auth_config = await get_oauth_runtime_config()
if not auth_config.ENABLE_OAUTH:
raise HTTPException(404)
if provider not in OAUTH_PROVIDERS:
raise HTTPException(404)
# If the provider has a custom redirect URL, use that, otherwise automatically generate one
@@ -1690,6 +1694,8 @@ class OAuthManager:
async def handle_callback(self, request, provider, response, db=None):
auth_config = await get_oauth_runtime_config()
if not auth_config.ENABLE_OAUTH:
raise HTTPException(404)
if provider not in OAUTH_PROVIDERS:
raise HTTPException(404)