{"record":{"id":"27c73f8988f12c25","repo":"siyuan-note/siyuan","slug":"a-public-https-oidc-redirect-url-is-required-for-r","errorCode":null,"errorMessage":"A public HTTPS OIDC redirect URL is required for remote access","messagePattern":"A public HTTPS OIDC redirect URL is required for remote access","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/oidc.go","lineNumber":574,"sourceCode":"\tif !util.IsLocalHost(host) {\n\t\treturn \"\", errors.New(\"A loopback OIDC redirect URL is required for local access\")\n\t}\n\treturn scheme + \"://\" + host + \"/api/system/oidc/callback\", nil\n}\n\nfunc oidcValidationRedirectURL(c *gin.Context, config *conf.OIDC, mobile bool) (string, error) {\n\tif mobile {\n\t\treturn oidcMobileRedirectURL, nil\n\t}\n\tif config.RedirectURL != \"\" {\n\t\treturn validatePublicOIDCRedirectURL(config.RedirectURL)\n\t}\n\treturn effectiveOIDCRedirectURL(c, oidcFlowDesktop)\n}\n\nfunc validatePublicOIDCRedirectURL(redirectURL string) (string, error) {\n\tif redirectURL == \"\" {\n\t\treturn \"\", errors.New(\"A public HTTPS OIDC redirect URL is required for remote access\")\n\t}\n\tparsed, err := url.Parse(redirectURL)\n\tif err != nil || parsed.Scheme == \"\" || parsed.Host == \"\" || parsed.Path != \"/api/system/oidc/callback\" ||\n\t\tparsed.User != nil || parsed.RawQuery != \"\" || parsed.Fragment != \"\" {\n\t\treturn \"\", errors.New(\"OIDC redirect URL must end with /api/system/oidc/callback\")\n\t}\n\tif parsed.Scheme != \"https\" {\n\t\treturn \"\", errors.New(\"Public OIDC redirect URL must use HTTPS\")\n\t}\n\treturn parsed.String(), nil\n}\n\nfunc getOIDCProvider(ctx context.Context, redirectURL string) (*oidc_provider.Provider, error) {\n\tversion := oidcConfigurationVersion(Conf.GetOIDC())\n\tkey := version + \"\\x00\" + redirectURL\n\toidcProviders.Lock()\n\tif oidcProviders.version != version {\n\t\toidcProviders.version = version","sourceCodeStart":556,"sourceCodeEnd":592,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/oidc.go#L556-L592","documentation":"validatePublicOIDCRedirectURL requires a non-empty redirect URL when validating remote access; an empty string gives it nothing to authenticate the callback against, so it errors rather than falling back to an insecure default.","triggerScenarios":"validatePublicOIDCRedirectURL(\"\") invoked from ValidateOIDCConfigurationChange, ValidateOIDCProviderConfiguration, oidcValidationRedirectURL, or effectiveOIDCRedirectURL when conf.OIDC.RedirectURL is unset and remote redirection is required.","commonSituations":"Fresh OIDC config saved with the public redirect field left blank while accessing remotely; config reset losing RedirectURL; administrator switching from local to remote access without filling in the URL.","solutions":["Set conf.OIDC.RedirectURL to the full public callback, e.g. https://your-domain/api/system/oidc/callback","Fill the redirect URL field in Settings - About/OIDC provider configuration before remote use","If only local use is intended, access via loopback so public URL validation is skipped"],"exampleFix":"// before\nRedirectURL: \"\"\n// after\nRedirectURL: \"https://siyuan.example.com/api/system/oidc/callback\"","handlingStrategy":"validation","validationCode":"if (!config.redirectURL || config.redirectURL.length === 0) { throw new Error('public redirect URL required for remote access'); }","typeGuard":null,"tryCatchPattern":"if err := ValidateOIDCConfigurationChange(ctx, cfg, true, false, false); err != nil {\n    if strings.Contains(err.Error(), \"public HTTPS OIDC redirect URL is required\") { /* prompt user to set RedirectURL */ }\n}","preventionTips":["Fill the public redirect URL whenever the instance is reachable from the internet","Keep the full callback path in your deployment notes/templates","Verify after config resets that RedirectURL was restored"],"tags":["oidc","redirect","config"],"backgroundTag":"missing-required-config-field","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}