nextcloud / nextcloud/talk-android
"State token does not match" error when using OpenID Provider
Nobody has claimed this yet.
- Dominant language
- Kotlin
- Stars
- 739
- Forks
- 321
- Avg merge
- 14h 59m
- Merged PRs (30d)
- 151
Description
Steps to reproduce
- Open the Nextcloud Talk app on an Android device.
- Select "Log in" and proceed to the OpenID Provider login page.
- Complete the OpenID Provider authentication steps as prompted.
Expected behaviour
Upon successfully authenticating with the OpenID Provider, the user should be seamlessly redirected back to the Nextcloud Talk app and logged in without any error messages. The session should begin with full access to Nextcloud Talk features, similar to the experience when logging in with a local Nextcloud account.
Actual behaviour
After completing authentication with the OpenID Provider, the following error message appears: "State token does not match." The login process fails, and the user is not logged into the Nextcloud Talk app.
Device brand and model
Google Pixel 7 Pro
Android version
14
Nextcloud Talk app version
20.0.2
Nextcloud server version
30.0.1
Talk version
20.0.1
Custom Signaling server configured
None
Custom TURN server configured
Yes
Custom STUN server configured
Yes
Android logs
No response
Server log
No response
Additional information
This "State token does not match" error also occurs when attempting to log in with an OpenID Provider in the main Nextcloud Android app. However, logging in via a web browser using the same OpenID Provider works without issues, and no error message is encountered. The OpenID Provider in use is Authentik.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the OpenID Provider login flow in the Nextcloud Talk Android app using the listed device and versions, then compare it with the working browser flow. The payload names no source files or tests and provides no Android or server logs; done means authentication returns to the app without a “State token does not match” error and establishes a session.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- android, kotlin
- Domain
- authentication, mobile
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100