From a97f5adf95016813ab992b68d15ef132bed060ae Mon Sep 17 00:00:00 2001 From: "Ethan T." Date: Mon, 9 Mar 2026 05:47:47 +0800 Subject: [PATCH] fix: URL-encode OAuth error message in redirect URL (#22415) - URL-encodes the OAuth error message when constructing the redirect URL in the OIDC callback handler - Without encoding, error messages containing spaces, ampersands, or other special characters produce malformed URLs that the frontend cannot parse correctly - The custom OAuth client callback handler already correctly uses urllib.parse.quote_plus() for the same purpose; this fix brings the OIDC handler in line with that pattern Co-authored-by: gambletan --- backend/open_webui/utils/oauth.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/backend/open_webui/utils/oauth.py b/backend/open_webui/utils/oauth.py index 249cc62d7..4b6568bee 100644 --- a/backend/open_webui/utils/oauth.py +++ b/backend/open_webui/utils/oauth.py @@ -1706,7 +1706,7 @@ class OAuthManager: redirect_url = f"{redirect_base_url}/auth" if error_message: - redirect_url = f"{redirect_url}?error={error_message}" + redirect_url = f"{redirect_url}?error={urllib.parse.quote_plus(error_message)}" return RedirectResponse(url=redirect_url, headers=response.headers) response = RedirectResponse(url=redirect_url, headers=response.headers)