{"record":{"id":"693b95ca92d96781","repo":"immich-app/immich","slug":"received-backchannel-logout-request-but-oauth-is-n","errorCode":null,"errorMessage":"Received backchannel logout request but OAuth is not enabled","messagePattern":"Received backchannel logout request but OAuth is not enabled","errorType":"exception","errorClass":"BadRequestException","httpStatus":400,"severity":"error","filePath":"server/src/services/auth.service.ts","lineNumber":97,"sourceCode":"  async logout(auth: AuthDto, authType: AuthType): Promise<LogoutResponseDto> {\n    let oauthBearerToken: string | undefined;\n    if (auth.session) {\n      const session = await this.sessionRepository.get(auth.session.id);\n      oauthBearerToken = session?.oauthBearerToken ?? undefined;\n      await this.sessionRepository.delete(auth.session.id);\n      await this.eventRepository.emit('SessionDelete', { sessionId: auth.session.id });\n    }\n\n    return {\n      successful: true,\n      redirectUri: await this.getLogoutEndpoint(authType, oauthBearerToken),\n    };\n  }\n\n  async backchannelLogout(dto: OAuthBackchannelLogoutDto): Promise<void> {\n    const { oauth } = await this.getConfig({ withCache: false });\n    if (!oauth.enabled) {\n      throw new BadRequestException('Received backchannel logout request but OAuth is not enabled');\n    }\n\n    let claims;\n    try {\n      claims = await this.oauthRepository.validateLogoutToken(oauth, dto.logout_token);\n    } catch (error: Error | any) {\n      this.logger.error(`Error backchannel logout: ${error.message}`);\n      this.logger.error(error);\n\n      throw new BadRequestException('Error backchannel logout: token validation failed');\n    }\n\n    if (!claims) {\n      throw new BadRequestException('Invalid logout token: no claims found');\n    }\n\n    if (!claims.sub && !claims.sid) {\n      throw new BadRequestException('Invalid logout token: it must contain either a sub or a sid claim');","sourceCodeStart":79,"sourceCodeEnd":115,"githubUrl":"https://github.com/immich-app/immich/blob/f48d4b332127ad365ba256108799ca8f571d2dd5/server/src/services/auth.service.ts#L79-L115","documentation":"backchannelLogout handles OIDC Back-Channel Logout requests from the identity provider. It first requires that OAuth is enabled in the server config; if oauth.enabled is false, the request is rejected with this BadRequestException (400) because there is no OAuth session machinery to process a logout for.","triggerScenarios":"The IdP posts a backchannel-logout request (with logout_token) to /api/oauth/backchannel-logout while the Immich server config has oauth.enabled === false — i.e. OAuth was disabled after the IdP was configured to send logout notifications.","commonSituations":"Admin disabling OAuth in Immich but forgetting to remove the back-channel logout URL in Keycloak/Auth0/Okta; IdP sending logout broadcasts to all registered clients after OAuth was toggled off; misconfigured instance pointing at the wrong server.","solutions":["Remove the Backchannel Logout URL from the OAuth client configuration in your identity provider, or point it at the correct Immich instance.","Re-enable OAuth (Administration > Settings > Authentication > OAuth) if the IdP logout notifications are expected.","Ignore/skip 400s for this endpoint in the IdP logs if OAuth is intentionally disabled.","Sync Immich's oauth.enabled setting with the IdP client registration lifecycle."],"exampleFix":"// before: IdP sends logout to a server with oauth disabled -> 400\n// after (Keycloak admin): remove the Backchannel Logout URL\n// Client > Advanced > Backchannel Logout URL: <empty> (OAuth disabled in Immich)","handlingStrategy":"try-catch","validationCode":"// IdP-side: only register the backchannel logout URL when Immich has oauth.enabled=true\nconst cfg = await api.getServerConfig();\nconsole.assert(cfg.oauthEnabled, 'Immich OAuth disabled; do not register backchannel logout URL');","typeGuard":null,"tryCatchPattern":"try { await idp.registerBackchannel(immichUrl); } catch (e) { logWarnOnce('Immich rejected backchannel logout; OAuth disabled'); }","preventionTips":["Remove backchannel logout URLs when disabling OAuth in Immich","Keep OAuth enablement symmetric between IdP client config and Immich settings","Filter expected 400s from IdP logs during intentional disablement"],"tags":["oauth","oidc","logout","config","immich"],"backgroundTag":"feature-not-enabled","analyzedSha":"f48d4b332127ad365ba256108799ca8f571d2dd5","analyzedAt":"2026-09-15T07:20:19.675Z","contentChangedAt":"2026-09-15T07:20:19.675Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}