{"record":{"id":"2a19c4d113ebc058","repo":"spring-projects/spring-security","slug":"unable-to-resolve-configuration-with-the-provided","errorCode":null,"errorMessage":"Unable to resolve Configuration with the provided Issuer of \"${issuer}\"","messagePattern":"Unable to resolve Configuration with the provided Issuer of \"(.+?)\"","errorType":"exception","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/registration/ClientRegistrations.java","lineNumber":290,"sourceCode":"\t\t\tSupplier<ClientRegistration.Builder>... suppliers) {\n\t\tString errorMessage = \"Unable to resolve Configuration with the provided Issuer of \\\"\" + issuer + \"\\\"\";\n\t\tList<String> errors = new ArrayList<>();\n\t\tfor (Supplier<ClientRegistration.Builder> supplier : suppliers) {\n\t\t\ttry {\n\t\t\t\treturn supplier.get();\n\t\t\t}\n\t\t\tcatch (HttpClientErrorException ex) {\n\t\t\t\tif (!ex.getStatusCode().is4xxClientError()) {\n\t\t\t\t\tthrow ex;\n\t\t\t\t}\n\t\t\t\terrors.add(ex.getMessage());\n\t\t\t\t// else try another endpoint\n\t\t\t}\n\t\t\tcatch (IllegalArgumentException | IllegalStateException ex) {\n\t\t\t\tthrow ex;\n\t\t\t}\n\t\t\tcatch (RuntimeException ex) {\n\t\t\t\tthrow new IllegalArgumentException(errorMessage, ex);\n\t\t\t}\n\t\t}\n\t\tif (!errors.isEmpty()) {\n\t\t\tthrow new IllegalArgumentException(errorMessage + \", errors: \" + errors);\n\t\t}\n\t\tthrow new IllegalArgumentException(errorMessage);\n\t}\n\n\tprivate static <T> T parseInput(Map<String, Object> body, ThrowingFunction<JSONObject, T, ParseException> parser) {\n\t\ttry {\n\t\t\treturn parse(body, parser);\n\t\t}\n\t\tcatch (RuntimeException ex) {\n\t\t\tthrow new IllegalArgumentException(ex);\n\t\t}\n\t}\n\n\tprivate static <T> T parse(Map<String, Object> body, ThrowingFunction<JSONObject, T, ParseException> parser) {","sourceCodeStart":272,"sourceCodeEnd":308,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/registration/ClientRegistrations.java#L272-L308","documentation":"ClientRegistrations.getBuilder fetches the OpenID/OAuth2 discovery document (.well-known/openid-configuration and .well-known/oauth-authorization-server) for the issuer and builds a registration from it. When no endpoint responds with a parseable configuration and no per-endpoint errors were collected, it throws this IllegalArgumentException with the issuer in the message.","triggerScenarios":"fromOidcIssuerLocation(issuer) or fromIssuerLocation(issuer) where every discovery URL fails (404, connection failure, non-JSON body) but no structured errors list was populated, falling through to the final throw.","commonSituations":"Typo in the issuer URL; issuer behind a firewall/VPN not reachable at build time; provider does not publish discovery metadata; HTTPS certificate issues; non-JSON responses failing silently.","solutions":["Verify the issuer URL in a browser/curl: https://issuer/.well-known/openid-configuration should return JSON with authorization_endpoint, token_endpoint, jwks_uri.","Fix network/TLS reachability (VPN, proxy, truststore) for the discovery host.","If the provider has no discovery endpoint, construct the ClientRegistration manually with explicit endpoints instead of ClientRegistrations.fromIssuerLocation.","Check for issuer path issues: discovery is fetched at issuer + '/.well-known/openid-configuration'; trailing slashes or path segments can break the lookup."],"exampleFix":"// before\nClientRegistration reg = ClientRegistrations.fromOidcIssuerLocation(\"https://idp.internal\"); // unreachable\n// after\nClientRegistration.withRegistrationId(\"idp\")\n    .authorizationUri(\"https://idp.internal/authorize\")\n    .tokenUri(\"https://idp.internal/token\")\n    .jwkSetUri(\"https://idp.internal/jwks\")\n    .userInfoUri(\"https://idp.internal/userinfo\")\n    .build();","handlingStrategy":"validation","validationCode":"// before calling ClientRegistrations, verify discovery is reachable\nRestTemplate rest = new RestTemplate();\nString meta = rest.getForEntity(\"https://issuer/.well-known/openid-configuration\", String.class).getBody();\nif (meta == null || !meta.trim().startsWith(\"{\")) throw new IllegalStateException(\"issuer has no discovery metadata\");","typeGuard":null,"tryCatchPattern":"try { ClientRegistrations.fromIssuerLocation(issuer); } catch (IllegalArgumentException e) { if (e.getMessage().startsWith(\"Unable to resolve Configuration\")) { /* use manual registration */ } throw e; }","preventionTips":["Validate issuer reachability at application startup, not first request","Use exact issuer strings as advertised by the provider","Keep the discovery path exempt from gateway auth"],"tags":["oauth2","oidc","discovery","network"],"backgroundTag":"resource-not-found","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}