{"record":{"id":"2a16186cbe5f64e7","repo":"siyuan-note/siyuan","slug":"discover-oauth-authorization-server-w","errorCode":null,"errorMessage":"discover OAuth authorization server: %w","messagePattern":"discover OAuth authorization server: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/mcp/client/oauth.go","lineNumber":214,"sourceCode":"\t\treturn fmt.Errorf(\"server returned %s\", resp.Status)\n\t}\n\tinteractive := h.interactive.Load()\n\tif interactive {\n\t\tdefer func() {\n\t\t\tif retErr != nil && !errors.Is(retErr, context.Canceled) {\n\t\t\t\tsetMCPRuntimeStateForContext(ctx, h.server.ID, \"authorization_required\", 0, retErr.Error(), \"\")\n\t\t\t}\n\t\t}()\n\t}\n\n\tprm, err := discoverProtectedResource(ctx, challenges, req.URL.String(), h.client)\n\tif err != nil {\n\t\treturn err\n\t}\n\n\tasm, err := auth.GetAuthServerMetadata(ctx, prm.AuthorizationServers[0], h.client)\n\tif err != nil {\n\t\treturn fmt.Errorf(\"discover OAuth authorization server: %w\", err)\n\t}\n\tif asm == nil {\n\t\treturn fmt.Errorf(\"OAuth authorization server metadata not found\")\n\t}\n\tcredential, hasCredential := getOAuthCredential(h.server.ID, h.server.URL)\n\tif hasCredential && credential.Issuer == asm.Issuer {\n\t\tcredential.TokenEndpoint = asm.TokenEndpoint\n\t\tcredential.RevocationEndpoint = asm.RevocationEndpoint\n\t}\n\tif hasCredential && credential.Issuer == asm.Issuer && credential.RefreshToken != \"\" &&\n\t\tchallengeError != \"insufficient_scope\" && !credential.Rejected && !oauthClientRegistrationExpired(credential) {\n\t\trefreshed, permanent, refreshErr := refreshOAuthCredential(ctx, h.client, credential)\n\t\tif refreshErr == nil {\n\t\t\tif saveErr := putOAuthCredential(refreshed); saveErr != nil {\n\t\t\t\tlogging.LogWarnf(\"mcp oauth: save refreshed credentials failed: %s\", saveErr)\n\t\t\t}\n\t\t\th.sourceMu.Lock()\n\t\t\th.source = &storedOAuthTokenSource{credential: refreshed, client: h.client}","sourceCodeStart":196,"sourceCodeEnd":232,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/mcp/client/oauth.go#L196-L232","documentation":"Wraps a failure from auth.GetAuthServerMetadata, which fetches the authorization server's RFC 8414 metadata (/.well-known/oauth-authorization-server) for the first authorization server advertised by the protected resource. The library throws this so callers can tell metadata discovery failures apart from later token/registration failures.","triggerScenarios":"Authorize reached the discovery step but GetAuthServerMetadata returned an error: the authorization-server URL is unreachable, DNS fails, TLS fails, the well-known endpoint 404s, or the response is not valid metadata JSON.","commonSituations":"Authorization server behind a firewall/VPN not currently connected; issuer URL typo in the resource metadata; well-known endpoints not deployed on the IdP; corporate proxy blocking the request; IdP down.","solutions":["Open https://<auth-server>/.well-known/oauth-authorization-server (and /.well-known/openid-configuration) in a browser to confirm metadata is served","Fix the authorization_servers entry in the resource metadata so it points at the real IdP issuer URL","Check network/proxy/VPN connectivity to the authorization server from the SiYuan host","Inspect the wrapped %w error in the message to identify transport vs parse failure and fix accordingly"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"meta, err := auth.GetAuthServerMetadata(ctx, authServerURL, http.DefaultClient)\nif err != nil {\n    return fmt.Errorf(\"pre-flight discovery failed: %w\", err)\n}","typeGuard":null,"tryCatchPattern":"if err := h.Authorize(ctx, req, resp); err != nil {\n    var discErr *fmt.Errorf // match on wrapped discovery error text\n    if strings.Contains(err.Error(), \"discover OAuth authorization server:\") {\n        retryLater(err)\n    }\n}","preventionTips":["Pre-flight check /.well-known/oauth-authorization-server reachability when adding an MCP server","Verify authorization_servers entries in the resource metadata resolve to live issuer URLs","Ensure firewalls/VPNs/proxies allow outbound HTTPS to the IdP from the SiYuan host"],"tags":["oauth","mcp","discovery","network"],"backgroundTag":"api-request-failed","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}