From 5d4505c68509242b72727e3493a5adb0f52a5530 Mon Sep 17 00:00:00 2001 From: pedro-inf-custodio <113921389+pedro-inf-custodio@users.noreply.github.com> Date: Sun, 8 Mar 2026 00:13:28 +0000 Subject: [PATCH] fix: add support for scope in OAuth refresh token request (#22359) * fix: add support for scope in OAuth refresh token request * add oauth refresh token include scope * Fix variable import * Fix env variables import * Added debug logs WIP * Remove debug logs --- backend/open_webui/config.py | 6 ++++++ backend/open_webui/utils/oauth.py | 22 ++++++++++++++++++++++ 2 files changed, 28 insertions(+) diff --git a/backend/open_webui/config.py b/backend/open_webui/config.py index 512bfdf7a..32dfdb7ca 100644 --- a/backend/open_webui/config.py +++ b/backend/open_webui/config.py @@ -339,6 +339,12 @@ ENABLE_OAUTH_SIGNUP = PersistentConfig( os.environ.get("ENABLE_OAUTH_SIGNUP", "False").lower() == "true", ) +OAUTH_REFRESH_TOKEN_INCLUDE_SCOPE = PersistentConfig( + "OAUTH_REFRESH_TOKEN_INCLUDE_SCOPE", + "oauth.refresh_token_include_scope", + os.environ.get("OAUTH_REFRESH_TOKEN_INCLUDE_SCOPE", "False").lower() == "true", +) + OAUTH_MERGE_ACCOUNTS_BY_EMAIL = PersistentConfig( "OAUTH_MERGE_ACCOUNTS_BY_EMAIL", diff --git a/backend/open_webui/utils/oauth.py b/backend/open_webui/utils/oauth.py index 284917d22..392ae74f9 100644 --- a/backend/open_webui/utils/oauth.py +++ b/backend/open_webui/utils/oauth.py @@ -36,6 +36,7 @@ from open_webui.models.groups import Groups, GroupModel, GroupUpdateForm, GroupF from open_webui.config import ( DEFAULT_USER_ROLE, ENABLE_OAUTH_SIGNUP, + OAUTH_REFRESH_TOKEN_INCLUDE_SCOPE, OAUTH_MERGE_ACCOUNTS_BY_EMAIL, OAUTH_PROVIDERS, ENABLE_OAUTH_ROLE_MANAGEMENT, @@ -113,6 +114,9 @@ log = logging.getLogger(__name__) auth_manager_config = AppConfig() auth_manager_config.DEFAULT_USER_ROLE = DEFAULT_USER_ROLE auth_manager_config.ENABLE_OAUTH_SIGNUP = ENABLE_OAUTH_SIGNUP +auth_manager_config.OAUTH_REFRESH_TOKEN_INCLUDE_SCOPE = ( + OAUTH_REFRESH_TOKEN_INCLUDE_SCOPE +) auth_manager_config.OAUTH_MERGE_ACCOUNTS_BY_EMAIL = OAUTH_MERGE_ACCOUNTS_BY_EMAIL auth_manager_config.ENABLE_OAUTH_ROLE_MANAGEMENT = ENABLE_OAUTH_ROLE_MANAGEMENT auth_manager_config.ENABLE_OAUTH_GROUP_MANAGEMENT = ENABLE_OAUTH_GROUP_MANAGEMENT @@ -787,6 +791,16 @@ class OAuthClientManager: if hasattr(client, "client_secret") and client.client_secret: refresh_data["client_secret"] = client.client_secret + # Add scope if available in client kwargs (some providers require it on refresh) + if ( + hasattr(client, "client_kwargs") + and client.client_kwargs.get("scope") + and getattr( + self.app.state.config, "OAUTH_REFRESH_TOKEN_INCLUDE_SCOPE", False + ) + ): + refresh_data["scope"] = client.client_kwargs["scope"] + # Make refresh request async with aiohttp.ClientSession(trust_env=True) as session_http: async with session_http.post( @@ -1081,6 +1095,14 @@ class OAuthManager: if hasattr(client, "client_secret") and client.client_secret: refresh_data["client_secret"] = client.client_secret + # Add scope if available in client kwargs (some providers require it on refresh) + if ( + hasattr(client, "client_kwargs") + and client.client_kwargs.get("scope") + and auth_manager_config.OAUTH_REFRESH_TOKEN_INCLUDE_SCOPE + ): + refresh_data["scope"] = client.client_kwargs["scope"] + # Make refresh request async with aiohttp.ClientSession(trust_env=True) as session_http: async with session_http.post(