nextcloud / nextcloud/user_oidc

Group provisioning does not work when user is auto-provisioned via Bearer token (only works with interactive login)

Open
#1,255 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

feature request priority: normal
Dominant language
PHP
Stars
181
Forks
60
Avg merge
7h 34m
Merged PRs (30d)
26

Description

Description

When using the user_oidc app with Zitadel as the OpenID Connect provider, group provisioning only works during interactive login through the Nextcloud web login page.
However, when the user is auto-provisioned via Bearer token (API or WebDAV request), the user is created correctly, but no groups are assigned, even though the identity provider sends the correct groups claim.

Expected behavior

When:

  • Check Bearer token on API and WebDAV requests is enabled
  • Auto provision user when accessing API and WebDAV with Bearer token is enabled
  • The Identity Provider (Zitadel) sends the groups claim containing the user’s groups

→ The Nextcloud user should be created with the same group assignments as if logging in through the web interface.

Actual behavior
  • When logging in via the browser → groups are created, added, and removed correctly according to what Zitadel provides.
  • When accessing any API endpoint or WebDAV using a valid OIDC Bearer token → user is auto-provisioned, but the groups claim is ignored. No groups are created or assigned.
Identity Provider
  • Zitadel (version 4)
  • Zitadel correctly sends the groups claim during both interactive login and Bearer-token authentication.
  • The decoded ID token / access token contains the same groups in both cases.
What I verified
  • The groups claim is present in the token received by Nextcloud (verified with token debugger).
  • Group provisioning is enabled in the user_oidc provider configuration.
  • No group whitelist regex is blocking or filtering the groups.
  • The same configuration works perfectly when using the web login flow.
  • Issue happens only during API/WebDAV auto-provisioning.
Steps to reproduce
  1. Configure user_oidc with Identity Provider(any), enabling:
    • Group provisioning
    • Check Bearer token on API and WebDAV requests
    • Auto provision user when accessing API and WebDAV with Bearer token
  2. Send an API or WebDAV request using a valid OIDC access token.
  3. Nextcloud auto-creates the user, but no groups are assigned.
  4. Log in with the same account via the browser → groups are provisioned correctly.
Environment
  • Nextcloud version: Nextcloud Hub 25 Autumn (32.0.1)
  • user_oidc app version: 8.1.0
  • Deployment: Docker
Impact

This prevents using OIDC for machine-to-machine or API-based workflows, since auto-provisioned users do not receive their required group permissions.

Additional information

I can provide debug logs showing that the groups claim is included in the token but not processed when the user is provisioned via Bearer token.

Image Image Image

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by comparing the interactive web login path with the API and WebDAV Bearer-token auto-provisioning path, focusing on how the token's groups claim is handled. Reproduce the issue with the listed configuration and an OIDC token, then verify that the auto-provisioned user's groups match those assigned during interactive login.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
authentication, authorization
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.