[Self-Hosted] SSO validation fails when OIDC provider returns issuer without trailing slash

(#731) Bug Fixed security self-hosting

Summary

When I use SSO from PocketID, the app_url is https://domain.com/ without a trailing slash. It works everywhere, except with Fluxer. When I configured it in the WebGUI, it automatically adds a trailing slash. So, when those 2 aren't the same, it gives an error: Invalid SSO Token. With the error being: JWTClaimValidationFailed: unexpected "iss" claim value claim: "iss" reason: "check_failed"

Steps to reproduce

Login SSO Use the button Use key Get error. When set issuer-url like: https://domain.com/ and it doesnt match with the provider issuer: https://domain.com/

Logs or screenshots

api-1 | {"level":"error","time":"DATE:TIME","service":"fluxer-api","env":"production","logger":"SsoService","error":{"type":"JWTClaimValidationFailed","message":"unexpected \"iss\" claim value","stack":"JWTClaimValidationFailed: unexpected \"iss\" claim value\n at validateClaimsSet (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/lib/jwt_claims_set.js:114:15)\n at jwtVerify (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/jwt/verify.js:9:21)\n at async SsoService.verifyIdToken (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:624:23)\n at async SsoService.resolveClaims (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:566:14)\n at async SsoService.completeLogin (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:332:18)\n at async AuthRequestService.toSsoCompleteResponse (/usr/src/app/fluxer_api/src/api/auth/AuthRequestService.ts:386:18)\n at async Object.handler (/usr/src/app/fluxer_api/src/api/auth/AuthController.ts:104:19)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)\n at async handler (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/hono-base.js:118:39)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)","code":"ERR_JWT_CLAIM_VALIDATION_FAILED","name":"JWTClaimValidationFailed","claim":"iss","reason":"check_failed","payload":{"amr":["phr"]

1 comment

Sign in with Fluxer to comment and vote.
Comment by @DarkMarkus88
RexSystem 1 vote originally by @DarkMarkus88 on GitHub OP
Dont know why, but with the latest version 2026.713.220414, when OIDC issuer_url set in WebGUI admin, the trailing slash stays gone and it is persistent after re-compose and restart. Closed for now.