{"record":{"id":"ad3a590ba3694f15","repo":"spring-projects/spring-security","slug":"login-required","errorCode":"login_required","errorMessage":"OAuth 2.0 Parameter: prompt","messagePattern":"OAuth 2\\.0 Parameter: prompt","errorType":"error_code","errorClass":"OAuth2AuthorizationCodeRequestAuthenticationException","httpStatus":null,"severity":"warning","filePath":"oauth2/oauth2-authorization-server/src/main/java/org/springframework/security/oauth2/server/authorization/authentication/OAuth2AuthorizationCodeRequestAuthenticationProvider.java","lineNumber":238,"sourceCode":"\t\t}\n\n\t\t// ---------------\n\t\t// The request is valid - ensure the resource owner is authenticated\n\t\t// ---------------\n\n\t\tAuthentication principal = (Authentication) authorizationCodeRequestAuthentication.getPrincipal();\n\n\t\tSet<String> promptValues = Collections.emptySet();\n\t\tif (authorizationCodeRequestAuthentication.getScopes().contains(OidcScopes.OPENID)) {\n\t\t\tString prompt = (String) authorizationCodeRequestAuthentication.getAdditionalParameters().get(\"prompt\");\n\t\t\tif (StringUtils.hasText(prompt)) {\n\t\t\t\tpromptValues = new HashSet<>(Arrays.asList(StringUtils.delimitedListToStringArray(prompt, \" \")));\n\t\t\t}\n\t\t}\n\n\t\tif (!isPrincipalAuthenticated(principal)) {\n\t\t\tif (promptValues.contains(OidcPrompt.NONE)) {\n\t\t\t\tthrow createException(\"login_required\", \"prompt\", authorizationCodeRequestAuthentication,\n\t\t\t\t\t\tregisteredClient);\n\t\t\t}\n\t\t\telse {\n\t\t\t\tthrow createException(OAuth2ErrorCodes.INVALID_REQUEST, \"principal\",\n\t\t\t\t\t\tauthorizationCodeRequestAuthentication, registeredClient);\n\t\t\t}\n\t\t}\n\n\t\tOAuth2AuthorizationRequest authorizationRequest = OAuth2AuthorizationRequest.authorizationCode()\n\t\t\t.authorizationUri(authorizationCodeRequestAuthentication.getAuthorizationUri())\n\t\t\t.clientId(registeredClient.getClientId())\n\t\t\t.redirectUri(authorizationCodeRequestAuthentication.getRedirectUri())\n\t\t\t.scopes(authorizationCodeRequestAuthentication.getScopes())\n\t\t\t.state(authorizationCodeRequestAuthentication.getState())\n\t\t\t.additionalParameters(authorizationCodeRequestAuthentication.getAdditionalParameters())\n\t\t\t.build();\n\t\tauthenticationContextBuilder.authorizationRequest(authorizationRequest);\n","sourceCodeStart":220,"sourceCodeEnd":256,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/oauth2/oauth2-authorization-server/src/main/java/org/springframework/security/oauth2/server/authorization/authentication/OAuth2AuthorizationCodeRequestAuthenticationProvider.java#L220-L256","documentation":"Thrown when the authorization request includes prompt=none (OIDC) but the end user is not currently authenticated at the authorization server (principal is anonymous). Per OIDC Core, prompt=none must fail with login_required instead of showing a login page.","triggerScenarios":"A client sends prompt=none (e.g., to silently check for an existing session / iframe renewal) while the user has no valid session — cookie missing, expired, or session invalidated on the server.","commonSituations":"Silent token renewal in hidden iframes when third-party cookies are blocked; session timeout on the auth server while the client still assumes a session; user cleared cookies; testing prompt=none without ever logging in.","solutions":["Treat login_required as expected: redirect the user to an interactive authentication (omit prompt=none) so they can log in","Re-establish the session at the authorization server before retrying the prompt=none request","Check why the session cookie was lost/expired (cookie SameSite settings for iframes, session timeout)","Only use prompt=none when an existing SSO session is actually expected"],"exampleFix":"// before\nString uri = authorize + \"?response_type=code&client_id=...&prompt=none\"; // fails when not logged in\n// after\n// handle login_required by falling back to interactive login\nif (error.equals(\"login_required\")) {\n    uri = authorize + \"?response_type=code&client_id=...\"; // no prompt=none\n}","handlingStrategy":"try-catch","validationCode":"// only send prompt=none if a session is expected\nboolean hasSession = sessionStatus != null && sessionStatus.hasSession();\nString prompt = hasSession ? \"none\" : null;","typeGuard":null,"tryCatchPattern":"try {\n    client.checkSessionSilently(promptNone);\n} catch (OAuth2AuthorizationCodeRequestAuthenticationException e) {\n    if (\"login_required\".equals(e.getError().getErrorCode())) {\n        // fall back to interactive authentication\n    }\n}","preventionTips":["Only use prompt=none when an SSO session is already expected","Handle login_required as a normal, recoverable outcome in OIDC clients","For iframes, configure cookies with SameSite=None; Secure to survive third-party contexts","Redirect the user to interactive login when login_required is received"],"tags":["oidc","prompt-none","sso-session"],"backgroundTag":"authentication-required","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}