{"record":{"id":"837a032591a3970c","repo":"immich-app/immich","slug":"oauth-is-not-enabled","errorCode":null,"errorMessage":"OAuth is not enabled","messagePattern":"OAuth is not enabled","errorType":"exception","errorClass":"BadRequestException","httpStatus":400,"severity":"error","filePath":"server/src/services/auth.service.ts","lineNumber":278,"sourceCode":"      return this.validateSession(session, headers);\n    }\n\n    if (apiKey) {\n      return this.validateApiKey(apiKey);\n    }\n\n    throw new UnauthorizedException('Authentication required');\n  }\n\n  getMobileRedirect(url: string) {\n    return `${MOBILE_REDIRECT}?${url.split('?', 2)[1] || ''}`;\n  }\n\n  async authorize(dto: OAuthConfigDto) {\n    const { oauth } = await this.getConfig({ withCache: false });\n\n    if (!oauth.enabled) {\n      throw new BadRequestException('OAuth is not enabled');\n    }\n\n    return await this.oauthRepository.authorize(\n      oauth,\n      this.resolveRedirectUri(oauth, dto.redirectUri),\n      dto.state,\n      dto.codeChallenge,\n    );\n  }\n\n  async callback(dto: OAuthCallbackDto, headers: IncomingHttpHeaders, loginDetails: LoginDetails) {\n    const { oauth } = await this.getConfig({ withCache: false });\n    if (!oauth.enabled) {\n      throw new BadRequestException('OAuth is not enabled');\n    }\n\n    const expectedState = dto.state ?? this.getCookieOauthState(headers);\n    if (!expectedState?.length) {","sourceCodeStart":260,"sourceCodeEnd":296,"githubUrl":"https://github.com/immich-app/immich/blob/f48d4b332127ad365ba256108799ca8f571d2dd5/server/src/services/auth.service.ts#L260-L296","documentation":"Thrown by authorize() when the OAuth configuration in server settings has enabled=false, fetched fresh with withCache:false. The OAuth login flow cannot start while the feature is disabled server-side.","triggerScenarios":"Starting an OAuth login while the admin setting OAuth Authentication is disabled (oauth.enabled false).","commonSituations":"Fresh install where OAuth was never enabled; admin toggled OAuth off; clients still show an OAuth button; pointing at the wrong server instance.","solutions":["Enable OAuth in admin settings (Administration > Settings > OAuth Authentication) with valid issuer/client ID/secret","Hide the OAuth login option in clients when OAuth is intentionally off","Clear stale cached config after changing settings","Verify you are targeting the correct server URL"],"exampleFix":"// before\nconst cfg = await getConfig(); if (cfg.oauth) startOAuth();\n// after\nconst cfg = await getConfig(); if (cfg.oauth?.enabled) startOAuth(); else usePasswordLogin();","handlingStrategy":"fallback","validationCode":"const { oauth } = await api.getConfig(); if (!oauth || !oauth.enabled) usePasswordLogin();","typeGuard":"const oauthReady = (c: { oauth?: { enabled?: boolean } }) => c.oauth?.enabled === true;","tryCatchPattern":"try { await api.startOAuth(dto) } catch (e) { if (e.status === 400 && /OAuth is not enabled/.test(e.message)) return passwordLogin(); throw e; }","preventionTips":["Gate OAuth UI on the server-reported enabled flag","Keep client and server OAuth settings in sync","Document OAuth setup in deployment configs"],"tags":["oauth","config","feature-disabled"],"backgroundTag":"feature-not-enabled","analyzedSha":"f48d4b332127ad365ba256108799ca8f571d2dd5","analyzedAt":"2026-09-15T07:20:19.675Z","contentChangedAt":"2026-09-15T07:20:19.675Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}