feat: add OAUTH_GROUPS_SEPARATOR for configurable group parsing#18987
Merged
tjbck merged 1 commit intoopen-webui:devfrom Nov 6, 2025
Merged
feat: add OAUTH_GROUPS_SEPARATOR for configurable group parsing#18987tjbck merged 1 commit intoopen-webui:devfrom
tjbck merged 1 commit intoopen-webui:devfrom
Conversation
Collaborator
|
Thanks! Let me do a brief code review |
Collaborator
|
looks correct, perhaps the env var can be retrieved within the oauth.py file then it does not have to get defined in the config.py and imported, it isn't used anywhere else after all (similar to the role separator env var). |
Contributor
|
LGTM, Thanks! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request Checklist
Note to first-time contributors: Please open a discussion post in Discussions to discuss your idea/fix with the community before creating a pull request, and describe your changes before submitting a pull request.
This is to ensure large feature PRs are discussed with the community first, before starting work on it. If the community does not want this feature or it is not relevant for Open WebUI as a project, it can be identified in the discussion before working on the feature and submitting the PR.
Before submitting, make sure you've checked the following:
devbranch. Not targeting thedevbranch will lead to immediate closure of the PR.Changelog Entry
Description
This PR implements support for semicolon-separated OAuth group claims, addressing issue #18979.
Added
Changed
Deprecated
n/a
Removed
n/a
Fixed
Security
n/a
Breaking Changes
n/a
Additional Information
Many OIDC providers like CILogon (supporting thousands of universities worldwide) return group membership as semicolon-separated strings in the affiliation claim (e.g., [email protected];[email protected];[email protected]).
Previously, this was treated as a single monolithic group name. Now it's properly parsed into individual groups.
Screenshots or Videos
Contributor License Agreement
By submitting this pull request, I confirm that I have read and fully agree to the Contributor License Agreement (CLA), and I am providing my contributions under its terms.