OAuth discovered metadata issuer does not match the expected issuer #5960

Closed
opened 2026-02-05 11:53:25 +03:00 by OVERLORD · 0 comments
Owner

Originally created by @jmarmstrong1207 on GitHub (May 4, 2025).

I have searched the existing issues, both open and closed, to make sure this is not a duplicate report.

  • Yes

The bug

Hello, I have changed the internal IP address of my authentik provider, and it shows this issue:

there seems to be no way for me to clear this metadata or cache. I have tried to turn off and on, and reset the settings of OAuth in the admin settings to no avail. Any fixes? Reverting back to the old internal IP fixes this issue

[Nest] 17  - 05/04/2025, 8:21:48 PM     LOG [Api:EventRepository] Websocket Connect:    KWjFUDpISCw3YkezAAAN
[Nest] 17  - 05/04/2025, 8:22:02 PM     LOG [Api:EventRepository] Websocket Disconnect: KWjFUDpISCw3YkezAAAN
[Nest] 17  - 05/04/2025, 8:22:04 PM   ERROR [Api:OAuthRepository~2zrr92dc] Error in OAuth discovery: ClientError: discovered metadata issuer does not match the expected issuer
[Nest] 17  - 05/04/2025, 8:22:04 PM   ERROR [Api:OAuthRepository~2zrr92dc] ClientError: discovered metadata issuer does not match the expected issuer
    at file:///usr/src/app/node_modules/openid-client/build/index.js:290:23
    at performDiscovery (file:///usr/src/app/node_modules/openid-client/build/index.js:298:15)
    at process.processTicksAndRejections (node:internal/process/task_queues:105:5)
    at async discovery (file:///usr/src/app/node_modules/openid-client/build/index.js:243:16)
    at async OAuthRepository.getClient (/usr/src/app/dist/repositories/oauth.repository.js:86:20)
    at async OAuthRepository.authorize (/usr/src/app/dist/repositories/oauth.repository.js:24:24)
    at async AuthService.authorize (/usr/src/app/dist/services/auth.service.js:124:16)
    at async OAuthController.startOAuth (/usr/src/app/dist/controllers/oauth.controller.js:36:46)

The OS that Immich Server is running on

LXC Debian Docker

Version of Immich Server

v1.132.3

Version of Immich Mobile App

Not related

Platform with the issue

  • Server
  • Web
  • Mobile

Your docker-compose.yml content

name: immich
services:
  immich-server:
    container_name: immich_server
    image: ghcr.io/immich-app/immich-server:${IMMICH_VERSION:-release}
    extends:
      file: hwaccel.transcoding.yml
      service: quicksync # set to one of [nvenc, quicksync, rkmpp, vaapi, vaapi-wsl] for accelerated transcoding
    volumes:
      # Do not edit the next line. If you want to change the media storage location on your system, edit the value of UPLOAD_LOCATION in the .env file
      - ${UPLOAD_LOCATION}:/usr/src/app/upload
      - /etc/localtime:/etc/localtime:ro
      - ./external:/external:ro
    env_file:
      - .env
    ports:
      - 2283:2283
    depends_on:
      - redis
      - database
    restart: always
    healthcheck:
      disable: false
  immich-machine-learning:
    container_name: immich_machine_learning
    # For hardware acceleration, add one of -[armnn, cuda, openvino] to the image tag.
    # Example tag: ${IMMICH_VERSION:-release}-cuda
    image: ghcr.io/immich-app/immich-machine-learning:${IMMICH_VERSION:-release}-openvino
    extends:
      # uncomment this section for hardware acceleration - see https://immich.app/docs/features/ml-hardware-acceleration
      file: hwaccel.ml.yml
      service: openvino # set to one of [armnn, cuda, openvino, openvino-wsl] for accelerated inference - use the `-wsl` version for WSL2 where applicable
    volumes:
      - model-cache:/cache
    env_file:
      - .env
    restart: always
    healthcheck:
      disable: false
  redis:
   container_name: immich_redis
    image: docker.io/valkey/valkey:8-bookworm@sha256:42cba146593a5ea9a622002c1b7cba5da7be248650cbb64ecb9c6c33d29794b1
    healthcheck:
      test: redis-cli ping || exit 1
    restart: always
  database:
    container_name: immich_postgres
    image: docker.io/tensorchord/pgvecto-rs:pg14-v0.2.0@sha256:739cdd626151ff1f796dc95a6591b55a714f341c737e27f045019ceabf8e8c52
    environment:
      POSTGRES_PASSWORD: ${DB_PASSWORD}
      POSTGRES_USER: ${DB_USERNAME}
      POSTGRES_DB: ${DB_DATABASE_NAME}
      POSTGRES_INITDB_ARGS: --data-checksums
    volumes:
      # Do not edit the next line. If you want to change the database storage location on your system, edit the value of DB_DATA_LOCATION in the .env file
      - ${DB_DATA_LOCATION}:/var/lib/postgresql/data
    healthcheck:
      test: pg_isready --dbname='${DB_DATABASE_NAME}' --username='${DB_USERNAME}' ||
        exit 1; Chksum="$$(psql --dbname='${DB_DATABASE_NAME}'
        --username='${DB_USERNAME}' --tuples-only --no-align --command='SELECT
        COALESCE(SUM(checksum_failures), 0) FROM pg_stat_database')"; echo
        "checksum failure count is $$Chksum"; [ "$$Chksum" = '0' ] || exit 1
      interval: 5m
      start_interval: 30s
      start_period: 5m
    command:
      - postgres
      - -c
      - shared_preload_libraries=vectors.so
      - -c
      - search_path="$$user", public, vectors
      - -c
      - logging_collector=on
      - -c
      - max_wal_size=2GB
      - -c
      - shared_buffers=512MB
      - -c
      - wal_compression=on
    restart: always
volumes:
  model-cache: null
networks: {}

Your .env content

# You can find documentation for all the supported env variables at https://immich.app/docs/install/environment-variables

# The location where your uploaded files are stored
UPLOAD_LOCATION=./library
# The location where your database files are stored
DB_DATA_LOCATION=./postgres

# To set a timezone, uncomment the next line and change Etc/UTC to a TZ identifier from this list: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List
# TZ=Etc/UTC

# The Immich version to use. You can pin this to a specific version like "v1.71.0"
IMMICH_VERSION=release

# Connection secret for postgres. You should change it to a random password
DB_PASSWORD=[REDACTED]

# The values below this line do not need to be changed
###################################################################################
DB_USERNAME=postgres
DB_DATABASE_NAME=immich

Reproduction steps

...

Relevant log output


Additional information

No response

Originally created by @jmarmstrong1207 on GitHub (May 4, 2025). ### I have searched the existing issues, both open and closed, to make sure this is not a duplicate report. - [x] Yes ### The bug Hello, I have changed the internal IP address of my authentik provider, and it shows this issue: there seems to be no way for me to clear this metadata or cache. I have tried to turn off and on, and reset the settings of OAuth in the admin settings to no avail. Any fixes? Reverting back to the old internal IP fixes this issue ``` [Nest] 17 - 05/04/2025, 8:21:48 PM LOG [Api:EventRepository] Websocket Connect: KWjFUDpISCw3YkezAAAN [Nest] 17 - 05/04/2025, 8:22:02 PM LOG [Api:EventRepository] Websocket Disconnect: KWjFUDpISCw3YkezAAAN [Nest] 17 - 05/04/2025, 8:22:04 PM ERROR [Api:OAuthRepository~2zrr92dc] Error in OAuth discovery: ClientError: discovered metadata issuer does not match the expected issuer [Nest] 17 - 05/04/2025, 8:22:04 PM ERROR [Api:OAuthRepository~2zrr92dc] ClientError: discovered metadata issuer does not match the expected issuer at file:///usr/src/app/node_modules/openid-client/build/index.js:290:23 at performDiscovery (file:///usr/src/app/node_modules/openid-client/build/index.js:298:15) at process.processTicksAndRejections (node:internal/process/task_queues:105:5) at async discovery (file:///usr/src/app/node_modules/openid-client/build/index.js:243:16) at async OAuthRepository.getClient (/usr/src/app/dist/repositories/oauth.repository.js:86:20) at async OAuthRepository.authorize (/usr/src/app/dist/repositories/oauth.repository.js:24:24) at async AuthService.authorize (/usr/src/app/dist/services/auth.service.js:124:16) at async OAuthController.startOAuth (/usr/src/app/dist/controllers/oauth.controller.js:36:46) ``` ### The OS that Immich Server is running on LXC Debian Docker ### Version of Immich Server v1.132.3 ### Version of Immich Mobile App Not related ### Platform with the issue - [x] Server - [ ] Web - [ ] Mobile ### Your docker-compose.yml content ```YAML name: immich services: immich-server: container_name: immich_server image: ghcr.io/immich-app/immich-server:${IMMICH_VERSION:-release} extends: file: hwaccel.transcoding.yml service: quicksync # set to one of [nvenc, quicksync, rkmpp, vaapi, vaapi-wsl] for accelerated transcoding volumes: # Do not edit the next line. If you want to change the media storage location on your system, edit the value of UPLOAD_LOCATION in the .env file - ${UPLOAD_LOCATION}:/usr/src/app/upload - /etc/localtime:/etc/localtime:ro - ./external:/external:ro env_file: - .env ports: - 2283:2283 depends_on: - redis - database restart: always healthcheck: disable: false immich-machine-learning: container_name: immich_machine_learning # For hardware acceleration, add one of -[armnn, cuda, openvino] to the image tag. # Example tag: ${IMMICH_VERSION:-release}-cuda image: ghcr.io/immich-app/immich-machine-learning:${IMMICH_VERSION:-release}-openvino extends: # uncomment this section for hardware acceleration - see https://immich.app/docs/features/ml-hardware-acceleration file: hwaccel.ml.yml service: openvino # set to one of [armnn, cuda, openvino, openvino-wsl] for accelerated inference - use the `-wsl` version for WSL2 where applicable volumes: - model-cache:/cache env_file: - .env restart: always healthcheck: disable: false redis: container_name: immich_redis image: docker.io/valkey/valkey:8-bookworm@sha256:42cba146593a5ea9a622002c1b7cba5da7be248650cbb64ecb9c6c33d29794b1 healthcheck: test: redis-cli ping || exit 1 restart: always database: container_name: immich_postgres image: docker.io/tensorchord/pgvecto-rs:pg14-v0.2.0@sha256:739cdd626151ff1f796dc95a6591b55a714f341c737e27f045019ceabf8e8c52 environment: POSTGRES_PASSWORD: ${DB_PASSWORD} POSTGRES_USER: ${DB_USERNAME} POSTGRES_DB: ${DB_DATABASE_NAME} POSTGRES_INITDB_ARGS: --data-checksums volumes: # Do not edit the next line. If you want to change the database storage location on your system, edit the value of DB_DATA_LOCATION in the .env file - ${DB_DATA_LOCATION}:/var/lib/postgresql/data healthcheck: test: pg_isready --dbname='${DB_DATABASE_NAME}' --username='${DB_USERNAME}' || exit 1; Chksum="$$(psql --dbname='${DB_DATABASE_NAME}' --username='${DB_USERNAME}' --tuples-only --no-align --command='SELECT COALESCE(SUM(checksum_failures), 0) FROM pg_stat_database')"; echo "checksum failure count is $$Chksum"; [ "$$Chksum" = '0' ] || exit 1 interval: 5m start_interval: 30s start_period: 5m command: - postgres - -c - shared_preload_libraries=vectors.so - -c - search_path="$$user", public, vectors - -c - logging_collector=on - -c - max_wal_size=2GB - -c - shared_buffers=512MB - -c - wal_compression=on restart: always volumes: model-cache: null networks: {} ``` ### Your .env content ```Shell # You can find documentation for all the supported env variables at https://immich.app/docs/install/environment-variables # The location where your uploaded files are stored UPLOAD_LOCATION=./library # The location where your database files are stored DB_DATA_LOCATION=./postgres # To set a timezone, uncomment the next line and change Etc/UTC to a TZ identifier from this list: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List # TZ=Etc/UTC # The Immich version to use. You can pin this to a specific version like "v1.71.0" IMMICH_VERSION=release # Connection secret for postgres. You should change it to a random password DB_PASSWORD=[REDACTED] # The values below this line do not need to be changed ################################################################################### DB_USERNAME=postgres DB_DATABASE_NAME=immich ``` ### Reproduction steps 1. 2. 3. ... ### Relevant log output ```shell ``` ### Additional information _No response_
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: immich-app/immich#5960