spring-projects/spring-security · warning · OAuth2AuthorizationCodeRequestAuthenticationException

login_required

login_required

Error message

OAuth 2.0 Parameter: prompt

What it means

Thrown when the authorization request includes prompt=none (OIDC) but the end user is not currently authenticated at the authorization server (principal is anonymous). Per OIDC Core, prompt=none must fail with login_required instead of showing a login page.

Solutions

  1. Treat login_required as expected: redirect the user to an interactive authentication (omit prompt=none) so they can log in
  2. Re-establish the session at the authorization server before retrying the prompt=none request
  3. Check why the session cookie was lost/expired (cookie SameSite settings for iframes, session timeout)
  4. Only use prompt=none when an existing SSO session is actually expected

Example fix

// before
String uri = authorize + "?response_type=code&client_id=...&prompt=none"; // fails when not logged in
// after
// handle login_required by falling back to interactive login
if (error.equals("login_required")) {
    uri = authorize + "?response_type=code&client_id=..."; // no prompt=none
}
Defensive patterns

Strategy: try-catch

Validate before calling

// only send prompt=none if a session is expected
boolean hasSession = sessionStatus != null && sessionStatus.hasSession();
String prompt = hasSession ? "none" : null;

Try / catch

try {
    client.checkSessionSilently(promptNone);
} catch (OAuth2AuthorizationCodeRequestAuthenticationException e) {
    if ("login_required".equals(e.getError().getErrorCode())) {
        // fall back to interactive authentication
    }
}

Prevention

When it happens

Trigger: A client sends prompt=none (e.g., to silently check for an existing session / iframe renewal) while the user has no valid session — cookie missing, expired, or session invalidated on the server.

Common situations: Silent token renewal in hidden iframes when third-party cookies are blocked; session timeout on the auth server while the client still assumes a session; user cleared cookies; testing prompt=none without ever logging in.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/ad3a590ba3694f15. Report an issue: GitHub.

Appendix: source

Thrown at oauth2/oauth2-authorization-server/src/main/java/org/springframework/security/oauth2/server/authorization/authentication/OAuth2AuthorizationCodeRequestAuthenticationProvider.java:238

		}

		// ---------------
		// The request is valid - ensure the resource owner is authenticated
		// ---------------

		Authentication principal = (Authentication) authorizationCodeRequestAuthentication.getPrincipal();

		Set<String> promptValues = Collections.emptySet();
		if (authorizationCodeRequestAuthentication.getScopes().contains(OidcScopes.OPENID)) {
			String prompt = (String) authorizationCodeRequestAuthentication.getAdditionalParameters().get("prompt");
			if (StringUtils.hasText(prompt)) {
				promptValues = new HashSet<>(Arrays.asList(StringUtils.delimitedListToStringArray(prompt, " ")));
			}
		}

		if (!isPrincipalAuthenticated(principal)) {
			if (promptValues.contains(OidcPrompt.NONE)) {
				throw createException("login_required", "prompt", authorizationCodeRequestAuthentication,
						registeredClient);
			}
			else {
				throw createException(OAuth2ErrorCodes.INVALID_REQUEST, "principal",
						authorizationCodeRequestAuthentication, registeredClient);
			}
		}

		OAuth2AuthorizationRequest authorizationRequest = OAuth2AuthorizationRequest.authorizationCode()
			.authorizationUri(authorizationCodeRequestAuthentication.getAuthorizationUri())
			.clientId(registeredClient.getClientId())
			.redirectUri(authorizationCodeRequestAuthentication.getRedirectUri())
			.scopes(authorizationCodeRequestAuthentication.getScopes())
			.state(authorizationCodeRequestAuthentication.getState())
			.additionalParameters(authorizationCodeRequestAuthentication.getAdditionalParameters())
			.build();
		authenticationContextBuilder.authorizationRequest(authorizationRequest);

View on GitHub (pinned to 96852e8860)