Steps to reproduce
- Run OpenCloud server
opencloudeu/opencloud-rolling:8.0.1 with the built-in IdP.
- On macOS, open OpenCloud Desktop. Reproduced on both 3.0.3.2073 and 4.0.0.3642.
- Add New Account, enter the server address, click Continue.
Expected behavior
The browser OAuth login completes and the account is saved, so the desktop client can sync.
Actual behavior
The desktop client cannot be used. Login never finishes and no account is stored. Both Desktop 3 and Desktop 4 fail, in different ways. Desktop 4 then hits a critical crash.
Desktop 4.0.0.3642. The wizard reaches the Login step and immediately shows Error while trying to log in to OAuth2-enabled server. The browser is not opened. Continue stays disabled. At the same moment the server access log shows the client issuing about 2,700 GET /.well-known/webfinger requests in roughly two seconds. Each returns HTTP 200 with a 142-byte body. There is no request to the OAuth authorize or token endpoints, and no server error log line for the attempt.
After that, Desktop 4 aborts. macOS crash reports from the same evening, both for 4.0.0.3642 on macOS 26.6.2 (25G83), SIGABRT / abort trap 6 (abort() called):
- 22:32. Abort on the main thread during AppKit startup (
NSApplication init → RegisterApplication).
- 22:46. Abort on a background thread.
QMessageLogger::fatal is called while constructing QEventDispatcherUNIX (QEventDispatcherUNIX::QEventDispatcherUNIX → QMessageLogger::fatal → abort).
Desktop 3.0.3.2073. The login link the client opens returns Forbidden.
This started after the server was upgraded to 8.0.1. I am not sure that upgrade is the cause, but desktop login worked before it, and it now fails on both the previous client (3.0.3.2073) and the current one (4.0.0.3642).
Setup
- macOS 26.6.2 (25G83), arm64 (the client About window reports
macos-26.6.0, QPA cocoa)
- Clients that fail: 3.0.3.2073 and 4.0.0.3642 (git
3f707e). The 4.0 About window reports Qt 6.11.1, OpenSSL 3.6.3 (9 Jun 2026), virtual files plugin off
- Server
opencloudeu/opencloud-rolling:8.0.1, built-in IdP
Screen recording
About 21 seconds, screen capture of the add-account wizard on Desktop 4.0.0.3642. Desktop 3 fails separately: its login link returns Forbidden. This recording is of 4.0.
- The About dialog confirms version 4.0.0.3642.
- Welcome step: "What is your server's address?" The server URL is entered and Continue is enabled.
- Continue is clicked.
- The Login step appears at once: "Connecting to" the server, "Log in with your web browser", and the buttons "Open web browser" and "Copy URL". A banner says "Error while trying to log in to OAuth2-enabled server." with Dismiss. Continue is disabled. The browser never opens.
- The wizard then falls back to an empty panel with a spinner. Welcome, Login, and Sync Options are unselected. Cancel is the only enabled control.
Client log
The macOS app is launched with stdout and stderr on /dev/null, and logHttp is false, so there is no client log file. The unified log has no OAuth error, only the process starting. The crashes above are the macOS diagnostic reports OpenCloud-2026-09-29-223223.ips and OpenCloud-2026-09-29-224605.ips.
Server log
From the opencloud container around the 4.0 attempt:
- about 2,721
GET /.well-known/webfinger, all status 200, 142 bytes, from the desktop client, within about 2 seconds
- no OAuth authorize or token request
- no error-level log line for the login
- unrelated periodic frontend warnings:
core access token not set on /status.php
Steps to reproduce
opencloudeu/opencloud-rolling:8.0.1with the built-in IdP.Expected behavior
The browser OAuth login completes and the account is saved, so the desktop client can sync.
Actual behavior
The desktop client cannot be used. Login never finishes and no account is stored. Both Desktop 3 and Desktop 4 fail, in different ways. Desktop 4 then hits a critical crash.
Desktop 4.0.0.3642. The wizard reaches the Login step and immediately shows Error while trying to log in to OAuth2-enabled server. The browser is not opened. Continue stays disabled. At the same moment the server access log shows the client issuing about 2,700
GET /.well-known/webfingerrequests in roughly two seconds. Each returns HTTP 200 with a 142-byte body. There is no request to the OAuth authorize or token endpoints, and no server error log line for the attempt.After that, Desktop 4 aborts. macOS crash reports from the same evening, both for 4.0.0.3642 on macOS 26.6.2 (25G83),
SIGABRT/ abort trap 6 (abort() called):NSApplicationinit →RegisterApplication).QMessageLogger::fatalis called while constructingQEventDispatcherUNIX(QEventDispatcherUNIX::QEventDispatcherUNIX→QMessageLogger::fatal→abort).Desktop 3.0.3.2073. The login link the client opens returns Forbidden.
This started after the server was upgraded to 8.0.1. I am not sure that upgrade is the cause, but desktop login worked before it, and it now fails on both the previous client (3.0.3.2073) and the current one (4.0.0.3642).
Setup
macos-26.6.0, QPA cocoa)3f707e). The 4.0 About window reports Qt 6.11.1, OpenSSL 3.6.3 (9 Jun 2026), virtual files plugin offopencloudeu/opencloud-rolling:8.0.1, built-in IdPScreen recording
About 21 seconds, screen capture of the add-account wizard on Desktop 4.0.0.3642. Desktop 3 fails separately: its login link returns Forbidden. This recording is of 4.0.
Client log
The macOS app is launched with stdout and stderr on
/dev/null, andlogHttpis false, so there is no client log file. The unified log has no OAuth error, only the process starting. The crashes above are the macOS diagnostic reportsOpenCloud-2026-09-29-223223.ipsandOpenCloud-2026-09-29-224605.ips.Server log
From the opencloud container around the 4.0 attempt:
GET /.well-known/webfinger, all status 200, 142 bytes, from the desktop client, within about 2 secondscore access token not seton/status.php