{"record":{"id":"35560f623cfca4ab","repo":"immich-app/immich","slug":"unable-to-register-profile-sub-normalizedemail-no-email-user","errorCode":null,"errorMessage":"Unable to register ${profile.sub}/${normalizedEmail || '(no email)'}. User does not exist and auto registering is disabled. To enable set OAuth Auto Register to true in admin settings.","messagePattern":"Unable to register (.+?)/(.+?)\\. User does not exist and auto registering is disabled\\. To enable set OAuth Auto Register to true in admin settings\\.","errorType":"console","errorClass":null,"httpStatus":null,"severity":"error","filePath":"server/src/services/auth.service.ts","lineNumber":338,"sourceCode":"        if (emailUser.oauthId) {\n          this.logger.debug('OAuth login conflict: email already linked to different account');\n          throw new BadRequestException('OAuth authentication failed');\n        }\n        user = await this.userRepository.update(emailUser.id, { oauthId: profile.sub });\n      }\n    }\n\n    const role = this.getRoleClaim(profile, roleClaim);\n    const isAdmin = role === 'admin';\n\n    if (user && role && isAdmin !== user.isAdmin) {\n      user = await this.userRepository.update(user.id, { isAdmin });\n    }\n\n    // register new user\n    if (!user) {\n      if (!autoRegister) {\n        this.logger.warn(\n          `Unable to register ${profile.sub}/${normalizedEmail || '(no email)'}. User does not exist and auto registering is disabled. To enable set OAuth Auto Register to true in admin settings.`,\n        );\n        throw new BadRequestException('OAuth authentication failed');\n      }\n\n      if (!normalizedEmail) {\n        throw new BadRequestException('OAuth profile does not have an email address');\n      }\n\n      this.logger.log(`Registering new user: ${profile.sub}/${normalizedEmail}`);\n\n      const storageLabel = this.getClaim(profile, {\n        key: storageLabelClaim,\n        default: '',\n        isValid: (value: unknown): value is string => typeof value === 'string',\n      });\n      const storageQuota = this.getClaim(profile, {\n        key: storageQuotaClaim,","sourceCodeStart":320,"sourceCodeEnd":356,"githubUrl":"https://github.com/immich-app/immich/blob/f48d4b332127ad365ba256108799ca8f571d2dd5/server/src/services/auth.service.ts#L320-L356","documentation":"In the OAuth callback, if no existing user matches the OAuth profile and auto-registration is disabled in admin settings, the server refuses to create an account: it logs this warning (including the OAuth subject and normalized email) and throws BadRequestException('OAuth authentication failed'). The user cannot sign in via OAuth until an account exists or auto-register is enabled.","triggerScenarios":"OAuth login/callback where getByOAuthId/getByEmail find no user and the autoRegister setting is false.","commonSituations":"Fresh OAuth login from a brand-new email on a server with OAuth Auto Register off; email changed at the IdP so it no longer matches; testing OAuth with a different account; migration where users were never provisioned.","solutions":["Enable 'OAuth Auto Register' in Administration > Settings > OAuth authentication.","Create the user account first (admin Users page) with matching email, then log in via OAuth.","Check the OAuth profile's email claim matches an existing user's email.","If the email legitimately changed, update the user's email in admin settings."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// before enabling OAuth login, ensure every expected IdP email has a server account\nconst emails = await idp.listEmails();\nfor (const email of emails) {\n  if (!(await server.userExistsByEmail(email))) console.warn(`No account for ${email}; enable auto-register or create it`);\n}","typeGuard":null,"tryCatchPattern":"try {\n  await api.oauthCallback(url);\n} catch (e) {\n  if (e instanceof BadRequestException && e.message.includes('OAuth authentication failed')) {\n    showToast('No account exists for this OAuth identity and auto-register is disabled');\n  } else throw e;\n}","preventionTips":["Enable OAuth Auto Register if any IdP user should get an account on first login.","Pre-provision accounts with emails matching the IdP's email claim.","Keep IdP emails in sync with server account emails (watch for email changes).","Test OAuth with the real account before rolling out to users."],"tags":["oauth","authentication","configuration"],"backgroundTag":"oauth-token-exchange-failed","analyzedSha":"f48d4b332127ad365ba256108799ca8f571d2dd5","analyzedAt":"2026-09-15T07:20:19.675Z","contentChangedAt":"2026-09-15T07:20:19.675Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}