From 91917b23952af8ca4457f8bb3db70c75ab838fbf Mon Sep 17 00:00:00 2001 From: Timothy Jaeryang Baek Date: Mon, 24 Aug 2026 17:16:01 -0400 Subject: [PATCH] refac --- backend/open_webui/main.py | 26 ++++++++++++++++++++++++-- backend/open_webui/routers/configs.py | 6 +++++- backend/open_webui/utils/oauth.py | 23 +++++++++++++++-------- 3 files changed, 44 insertions(+), 11 deletions(-) diff --git a/backend/open_webui/main.py b/backend/open_webui/main.py index a629011362..3708a192ae 100644 --- a/backend/open_webui/main.py +++ b/backend/open_webui/main.py @@ -13,6 +13,7 @@ from uuid import uuid4 import aiohttp import anyio.to_thread +from cryptography.fernet import InvalidToken from fastapi import ( Depends, FastAPI, @@ -625,8 +626,18 @@ async def initialize_runtime_config(app: FastAPI): f'mcp:{server_id}', OAuthClientInformationFull(**oauth_client_info), ) + except InvalidToken: + log.error( + 'Error adding OAuth client for MCP tool server %s: InvalidToken. ' + 'Stored OAuth client data is invalid; reconnect this tool server.', + server_id, + ) except Exception as e: - log.error(f'Error adding OAuth client for MCP tool server {server_id}: {e}') + log.error( + 'Error adding OAuth client for MCP tool server %s: %s', + server_id, + f'{type(e).__name__}: {e}' if str(e) else type(e).__name__, + ) arena_models = await Config.get('evaluation.arena.models', []) or [] if any('access_control' in m.get('meta', {}) for m in arena_models): @@ -2686,8 +2697,19 @@ async def register_client(request, client_id: str) -> bool: oauth_server_key, oauth_scope=oauth_scope, ) + except InvalidToken: + log.error( + 'OAuth client re-registration failed for %s: InvalidToken. ' + 'Stored OAuth client data is invalid; reconnect this tool server.', + client_id, + ) + return False except Exception as e: - log.error(f'OAuth client re-registration failed for {client_id}: {e}') + log.error( + 'OAuth client re-registration failed for %s: %s', + client_id, + f'{type(e).__name__}: {e}' if str(e) else type(e).__name__, + ) return False try: diff --git a/backend/open_webui/routers/configs.py b/backend/open_webui/routers/configs.py index f591908a6d..38cd4d15a0 100644 --- a/backend/open_webui/routers/configs.py +++ b/backend/open_webui/routers/configs.py @@ -279,7 +279,11 @@ async def set_tool_servers_config( OAuthClientInformationFull(**oauth_client_info), ) except Exception as e: - log.debug('Failed to add OAuth client for MCP tool server: %s', e) + log.debug( + 'Failed to add OAuth client for MCP tool server %s: %s', + server_id, + f'{type(e).__name__}: {e}' if str(e) else type(e).__name__, + ) continue await publish_event( diff --git a/backend/open_webui/utils/oauth.py b/backend/open_webui/utils/oauth.py index 0c28ff4a04..278ff9e2e6 100644 --- a/backend/open_webui/utils/oauth.py +++ b/backend/open_webui/utils/oauth.py @@ -18,7 +18,7 @@ import jwt from authlib.integrations.starlette_client import OAuth from authlib.oauth2.rfc6749.errors import OAuth2Error from authlib.oidc.core import UserInfo -from cryptography.fernet import Fernet +from cryptography.fernet import Fernet, InvalidToken from fastapi import ( HTTPException, status, @@ -275,12 +275,8 @@ def encrypt_data(data) -> str: def decrypt_data(data: str): """Decrypt data from storage""" - try: - decrypted = FERNET.decrypt(data.encode()).decode() - return JSONCodec.loads(decrypted) - except Exception as e: - log.error(f'Error decrypting data: {e}') - raise + decrypted = FERNET.decrypt(data.encode()).decode() + return JSONCodec.loads(decrypted) def _build_oauth_callback_error_message(e: Exception) -> str: @@ -909,8 +905,19 @@ class OAuthClientManager: oauth_client_info = await recover_static_oauth_client_metadata(connection, oauth_client_info) oauth_client_info = apply_connection_oauth_options(connection, oauth_client_info) return self.add_client(expected_client_id, OAuthClientInformationFull(**oauth_client_info))['client'] + except InvalidToken: + log.error( + 'Failed to lazily add OAuth client %s from config: InvalidToken. ' + 'Stored OAuth client data is invalid; reconnect this tool server.', + expected_client_id, + ) + continue except Exception as e: - log.error(f'Failed to lazily add OAuth client {expected_client_id} from config: {e}') + log.error( + 'Failed to lazily add OAuth client %s from config: %s', + expected_client_id, + f'{type(e).__name__}: {e}' if str(e) else type(e).__name__, + ) continue return None