spring-projects/spring-security · warning · OAuth2AuthorizationCodeRequestAuthenticationException
login_required
login_required
Error message
OAuth 2.0 Parameter: prompt
What it means
Thrown when the authorization request includes prompt=none (OIDC) but the end user is not currently authenticated at the authorization server (principal is anonymous). Per OIDC Core, prompt=none must fail with login_required instead of showing a login page.
Solutions
- Treat login_required as expected: redirect the user to an interactive authentication (omit prompt=none) so they can log in
- Re-establish the session at the authorization server before retrying the prompt=none request
- Check why the session cookie was lost/expired (cookie SameSite settings for iframes, session timeout)
- Only use prompt=none when an existing SSO session is actually expected
Example fix
// before
String uri = authorize + "?response_type=code&client_id=...&prompt=none"; // fails when not logged in
// after
// handle login_required by falling back to interactive login
if (error.equals("login_required")) {
uri = authorize + "?response_type=code&client_id=..."; // no prompt=none
} Defensive patterns
Strategy: try-catch
Validate before calling
// only send prompt=none if a session is expected boolean hasSession = sessionStatus != null && sessionStatus.hasSession(); String prompt = hasSession ? "none" : null;
Try / catch
try {
client.checkSessionSilently(promptNone);
} catch (OAuth2AuthorizationCodeRequestAuthenticationException e) {
if ("login_required".equals(e.getError().getErrorCode())) {
// fall back to interactive authentication
}
} Prevention
- Only use prompt=none when an SSO session is already expected
- Handle login_required as a normal, recoverable outcome in OIDC clients
- For iframes, configure cookies with SameSite=None; Secure to survive third-party contexts
- Redirect the user to interactive login when login_required is received
When it happens
Trigger: A client sends prompt=none (e.g., to silently check for an existing session / iframe renewal) while the user has no valid session — cookie missing, expired, or session invalidated on the server.
Common situations: Silent token renewal in hidden iframes when third-party cookies are blocked; session timeout on the auth server while the client still assumes a session; user cleared cookies; testing prompt=none without ever logging in.
Related errors
- consent_required
- An error occurred reading the OpenID Client Registration
- An error occurred reading the OpenID Provider Configuration
- An error occurred writing the OpenID Client Registration
- insufficient_scope
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/ad3a590ba3694f15.
Report an issue: GitHub.
Appendix: source
Thrown at oauth2/oauth2-authorization-server/src/main/java/org/springframework/security/oauth2/server/authorization/authentication/OAuth2AuthorizationCodeRequestAuthenticationProvider.java:238
}
// ---------------
// The request is valid - ensure the resource owner is authenticated
// ---------------
Authentication principal = (Authentication) authorizationCodeRequestAuthentication.getPrincipal();
Set<String> promptValues = Collections.emptySet();
if (authorizationCodeRequestAuthentication.getScopes().contains(OidcScopes.OPENID)) {
String prompt = (String) authorizationCodeRequestAuthentication.getAdditionalParameters().get("prompt");
if (StringUtils.hasText(prompt)) {
promptValues = new HashSet<>(Arrays.asList(StringUtils.delimitedListToStringArray(prompt, " ")));
}
}
if (!isPrincipalAuthenticated(principal)) {
if (promptValues.contains(OidcPrompt.NONE)) {
throw createException("login_required", "prompt", authorizationCodeRequestAuthentication,
registeredClient);
}
else {
throw createException(OAuth2ErrorCodes.INVALID_REQUEST, "principal",
authorizationCodeRequestAuthentication, registeredClient);
}
}
OAuth2AuthorizationRequest authorizationRequest = OAuth2AuthorizationRequest.authorizationCode()
.authorizationUri(authorizationCodeRequestAuthentication.getAuthorizationUri())
.clientId(registeredClient.getClientId())
.redirectUri(authorizationCodeRequestAuthentication.getRedirectUri())
.scopes(authorizationCodeRequestAuthentication.getScopes())
.state(authorizationCodeRequestAuthentication.getState())
.additionalParameters(authorizationCodeRequestAuthentication.getAdditionalParameters())
.build();
authenticationContextBuilder.authorizationRequest(authorizationRequest);
View on GitHub (pinned to 96852e8860)