actualbudget / actualbudget/actual
[Bug]: OIDC With Entra Not Authenticating Additional Users
- Lingua principale
- TypeScript
- Stelle
- 28.8k
- Fork
- 3k
- Merge medio
- 2g 11h
- PR unite (30g)
- 65
Descrizione
### Verified issue does not already exist?
- [x] I have searched and found no existing issue
### What happened?
I have configured OIDC with an app registration in Entra and it is working fine to authenticate the account set as server owner. Whenever I authentication a second user (already added under User Directory) it throws "openid-grant-failed". The journal is linked below for review, most relevant line reads **OAuth2 Authorization code was already redeemed, please retry with a new valid code or use an existing refresh token**. The sign-in logs Entra-side show successful authentication. I also noticed that when I authenticated my account with OIDC, it set my username in User Directory as some sort of guid:
Log: https://pastebin.com/YeWFFVUJ
### How can we reproduce the issue?
Actual is being hosted on a home server running Debian 12. Entra is set up as IdP using an App Registration.
### Where are you hosting Actual?
Locally via Yarn
### What browsers are you seeing the problem on?
Chrome
### Operating System
Windows 11
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
Start with the OIDC sign-in flow using the Entra app registration and compare the server-owner and additional-user paths; review the linked journal for the authorization-code redemption failure. Reproduce locally via Yarn on Debian 12, then verify that a second User Directory account authenticates without openid-grant-failed and that its username mapping is handled consistently.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- azure, typescript
- Ambito
- authentication, backend
- Tipo di issue
- Bug
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Stato di attività
- Tranquilla
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 48/100