Files
open-webui/backend/open_webui/utils
Classic298 5462c02af0 fix: OIDC login fails when the provider adds a private JOSE header (#28065)
Logging in through CyberArk Identity dies at the callback with "Unsupported {'app_id'} in header" and the user sees "The email or password provided is incorrect". Any provider that puts a vendor-specific parameter in the ID token header hits this; CAS was already patched by name, CyberArk is the next one.

Authlib 1.7 verifies ID tokens with joserfc, which rejects header parameters it does not recognise. The old fix registered `client_id` so CAS would work, which only ever fixes one provider at a time. This turns off the unknown-header rejection instead, so any private header parameter is ignored rather than fatal. Signature verification, the algorithm allowlist, `crit` handling and value validation of registered headers all still run, so nothing that actually protects the token is relaxed.

Fixes #28062
2026-08-10 20:06:31 -06:00
..
2026-06-29 11:56:00 -05:00
2026-07-31 17:41:14 -04:00
2026-08-05 10:37:38 -05:00
2026-07-31 17:30:47 -04:00
2026-03-17 17:58:01 -05:00
2026-07-23 02:54:56 -04:00
2026-07-26 21:12:14 -04:00
2026-07-31 17:41:14 -04:00
2026-07-31 17:41:14 -04:00
2026-07-31 17:41:14 -04:00
2026-07-23 21:29:33 -04:00
2026-07-27 00:12:47 -04:00
2026-07-31 17:41:14 -04:00
2026-08-10 19:28:21 -06:00
2026-08-10 19:41:05 -06:00
2026-08-10 19:41:05 -06:00
2026-07-26 23:09:22 -04:00
2026-07-27 19:39:36 -04:00
2026-08-10 19:41:05 -06:00
2026-07-31 17:41:14 -04:00
2026-03-17 17:58:01 -05:00
2026-07-27 04:17:00 -04:00
2026-07-31 17:41:14 -04:00
2026-06-19 00:16:06 +02:00
2026-08-08 15:47:10 -06:00
2026-07-31 17:41:14 -04:00
2026-08-10 19:44:56 -06:00
2026-07-27 19:39:36 -04:00
2026-07-31 17:41:14 -04:00