Modify ↓

Opened 9 hours ago

Last modified 4 hours ago

#24925 new defect

oauth2 for a non-OSM/OHM openstreetmap-website instance fails

Reported by: petergboswell@… Owned by: team
Priority: normal Milestone:
Component: Core Version:
Keywords: template_report Cc:

Description

I have a problem with the user-facing way to authenticate JOSM against a non-OSM/OHM openstreetmap-website instance which has basic authentication disabled.

I have oauth2 set up for a Panoramax instance amongst other things so have some understanding of the issues.

My OSM website has a doorkeeper signing key and the JOSM Oauth 2 Appplication is set up in the normal way.

What steps will reproduce the problem?

Clear out JOSM preferences leaving only an oauth.access-token.parameters.OAuth20.https://osm.mysite.net/api' entry for my OSM website

In JOSM Version 19627, download an area and move a node.

Click upload that givies panels saying "Uploading data..." and "Obtain authentication to OSM server"

Click "Yes" and browser opens at my OSM website (osm.mysite.net)

Log in and the page gives the often mentioned "Missing required parameter:client_id" at:

​https://osm.mysite.net/oauth2/authorize?response_type=code&client_id=&redirect_uri=http://127.0.0.1:8111/oauth_authorization&scope=read_gpx%20write_gpx%20read_prefs%20write_prefs%20write_api%20write_notes&state=22da5bc2-e3e1-4b85-a77e-38bba8d20b63&code_challenge_method=S256&code_challenge=Lxtb2JyoY6iCTIj9jzNOxSUzAZSgjROSq02hdT8Cdek

Paste in the OSM website Client ID into the URL and resubmit.

  • Rails port console gives: Doorkeeper grant - "token", "p_bohEToJ1l3AOV8G3IAhXlgSB3KS5BxGK160iHX2Ow"

Back in JOSM Preferences, click "Authorise now (Manual)" and enter the token as the Access Token Key.

Clicking "Test Access Token " fails (Failed to access the OSM server '​https://osm.mysite.net/api' with the Access Token 'p_bohEToJ1l3AOV8G3IAhXlgSB3KS5BxGK160iHX2Ow'.The server rejected the Access Token as unauthorised.)

Rails port console now has a second Doorkeeper entry with "token", "06cc923ca6d5a1cb1175bc6a608581b5e394a6dccc7b11119f16a15ceb4be33d"

As expected, nothing has been written to preferences.xml.

JOSM is frozen

Restart JOSM, enter the advanced manual information, click "Authorise now (manual)" and enter the second token.

The second token fails with "Failed to retrieve information about the current user from the OSM server '​https://osm.mysite.net/api')

What is the expected result?

Authentication

What happens instead?

Authenticaion fails

Please provide any additional information below. Attach a screenshot if possible.

Relative:URL: ^/trunk
Repository:UUID: 0c6e7542-c601-0410-84e7-c038aed88b3b
Last:Changed Date: 2026-09-20 21:33:09 +0200 (Sun, 20 Sep 2026)
Revision:19627
Build-Date:2026-09-21 01:30:50
URL:https://josm.openstreetmap.de/svn/trunk

Identification: JOSM/1.5 (19627 en_GB) Windows 11 64-Bit
OS Build number: Windows 10 Pro 25H2 (26200)
Memory Usage: 712 MB / 16328 MB (433 MB allocated, but free)
Java version: 18.0.1.1+2-6, Oracle Corporation, Java HotSpot(TM) 64-Bit Server VM
Look and Feel: com.sun.java.swing.plaf.windows.WindowsLookAndFeel
Screen: \Display0 1920x1080x32bpp@60Hz (scaling 1.00×1.00)
Maximum Screen Size: 1920×1080
Best cursor sizes: 16×16→32×32, 32×32→32×32
System property file.encoding: UTF-8
System property sun.jnu.encoding: Cp1252
Locale info: en_GB
Numbers with default locale: 1234567890 -> 1234567890

Plugins:
+ ImportImagePlugin (36503)
+ PicLayer (275)
+ apache-commons (36483)
+ ejml (36483)
+ geotools (36483)
+ imagery_offset_db (36503)
+ jackson (36502)
+ jaxb (36483)
+ jts (36483)
+ mbtiles (v2.8.1)
+ photo_geotagging (36503)
+ photoadjust (36503)

Last errors/warnings:
- 00000.372 W: extended font config - overriding 'filename.Myanmar_Text=mmrtext.ttf' with 'MMRTEXT.TTF'
- 00000.373 W: extended font config - overriding 'filename.Mongolian_Baiti=monbaiti.ttf' with 'MONBAITI.TTF'
- 00002.023 W: Update plug-ins - You updated your JOSM software. To prevent problems the plug-ins should be updated as well.  Update plug-ins now?

OSM API: https://osm.mysite.net/api

Attachments (0)

Change History (5)

comment:1 by wangi, 7 hours ago

Just to join the dots, r19627 is when #24890 and #24889 were merged, both OAuth related.

I note the step you clear configuration out and then only try to complete the process on upload. What happens if you try to do it all upfront in the preferences dialog?

comment:2 by wangi, 6 hours ago

To answer myself... I commented out my test server from OAuthParameters.java.

  • Clear out authentication, put in the custom API, validate and close dialog... Make an edit, upload and get the same issue as OP.
  • Clear out authentication, put in the custom API, validate, show advanced OAuth params, enter client ID and secret from a created non-confidential OAuth 2 Application on the site with the correct perms and redirect URL, authorise automatically = success

comment:3 by petergboswell@…, 6 hours ago

Thank you for the feedback. I'll have a look at having up-front preferences.

comment:4 by anonymous, 4 hours ago

I think the second works (I am checking to see that a node in the database is added).

I simply removed the tag for the key='oauth.access-token.parameters.OAuth20.https://osm.mysite.net/api' from preferences.xml.

Closed the browser, ran JOSM and added the Advanced Oauth Parameters.

The automatic button was now active: Clicking the button opened the browser at the OSM-website login. Logged in and received a page saying 'OK'.

An Access Token Key was now displayed in JOSM.

If the database is indeed updated, many, many thanks. Being able to use JOSM with a self-hosted Oauth2 OSM-website is essential

comment:5 by anonymous, 4 hours ago

The database is updated!

Modify Ticket

Change Properties
Set your email in Preferences
Action
as new The owner will remain team.
as The resolution will be set. Next status will be 'closed'.
to The owner will be changed from team to the specified user.
Next status will be 'needinfo'. The owner will be changed from team to petergboswell@….
as duplicate The resolution will be set to duplicate. Next status will be 'closed'. The specified ticket will be cross-referenced with this ticket.
The owner will be changed from team to anonymous. Next status will be 'assigned'.

Add Comment


E-mail address and name can be saved in the Preferences .
 
Note: See TracTickets for help on using tickets.