{"record":{"id":"2efac30966d581d1","repo":"siyuan-note/siyuan","slug":"github-oauth-client-secret-is-required","errorCode":null,"errorMessage":"GitHub OAuth client secret is required","messagePattern":"GitHub OAuth client secret is required","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/oidc.go","lineNumber":463,"sourceCode":"\tif !cancelOIDCValidation(input.PollToken, workspaceSession.OIDCBinding) {\n\t\tret = apicontract.Failure[apicontract.Null](-1, oidcLanguage(369, \"Invalid OIDC configuration\"))\n\t}\n\treturn\n}\n\nfunc validateOIDCConfiguration() error {\n\treturn ValidateOIDCConfiguration(Conf.GetOIDC())\n}\n\nfunc ValidateOIDCConfiguration(config *conf.OIDC) error {\n\tif config == nil || !config.Enabled {\n\t\treturn errors.New(\"OIDC login is not enabled\")\n\t}\n\tif config.ClientID == \"\" {\n\t\treturn errors.New(\"OIDC client ID is required\")\n\t}\n\tif config.Provider == conf.OIDCProviderGitHub && config.ClientSecret == \"\" {\n\t\treturn errors.New(\"GitHub OAuth client secret is required\")\n\t}\n\tif (config.Provider == conf.OIDCProviderCustom || config.Provider == conf.OIDCProviderMicrosoft) && config.IssuerURL == \"\" {\n\t\treturn errors.New(\"OIDC issuer URL is required\")\n\t}\n\tif (config.Provider == conf.OIDCProviderCustom || config.Provider == conf.OIDCProviderMicrosoft) && config.IssuerURL != \"\" {\n\t\tissuer, err := url.Parse(config.IssuerURL)\n\t\tif err != nil || issuer.Host == \"\" || issuer.User != nil || issuer.RawQuery != \"\" || issuer.Fragment != \"\" ||\n\t\t\t(issuer.Scheme != \"https\" && !util.IsLocalHostname(issuer.Hostname())) {\n\t\t\treturn errors.New(\"OIDC issuer URL must use HTTPS unless it is a loopback address\")\n\t\t}\n\t}\n\tif config.Provider != conf.OIDCProviderCustom && config.Provider != conf.OIDCProviderGoogle &&\n\t\tconfig.Provider != conf.OIDCProviderMicrosoft && config.Provider != conf.OIDCProviderGitHub {\n\t\treturn errors.New(\"Unsupported OIDC provider\")\n\t}\n\tif !config.AllowAll && len(config.ClaimRules) == 0 {\n\t\treturn errors.New(\"OIDC login requires at least one claim rule when Allow all users is disabled\")\n\t}","sourceCodeStart":445,"sourceCodeEnd":481,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/oidc.go#L445-L481","documentation":"When the OIDC provider is GitHub, ValidateOIDCConfiguration additionally requires a non-empty ClientSecret. GitHub's OAuth flow needs the client secret for the token exchange, so an enabled GitHub provider with an empty secret is rejected with \"GitHub OAuth client secret is required\" before any network call is made.","triggerScenarios":"Calling ValidateOIDCConfiguration (directly or via validateOIDCConfiguration/ValidateOIDCMobileConfiguration/ValidateOIDCProviderConfiguration) with config.Provider == conf.OIDCProviderGitHub and config.ClientSecret == \"\" — enabling GitHub login without entering the secret.","commonSituations":"Filling in only the client ID and assuming the secret is optional; losing the secret after a config restore; using a secret that was reset in the GitHub developer settings and cleared locally; swapping providers from Google to GitHub without adding a secret.","solutions":["Generate/copy the client secret from the GitHub OAuth App settings and paste it into the OIDC Client Secret field.","If the secret was reset in GitHub, create a new one and update the SiYuan configuration.","Re-save the settings and confirm the secret persisted in the workspace config before retrying login.","If GitHub login is not actually wanted, switch the provider field to the intended provider so the GitHub-specific secret check no longer applies."],"exampleFix":"// before\nconfig := &conf.OIDC{Enabled: true, Provider: conf.OIDCProviderGitHub, ClientID: \"Iv1.abc\"}\n// after\nconfig := &conf.OIDC{Enabled: true, Provider: conf.OIDCProviderGitHub, ClientID: \"Iv1.abc\", ClientSecret: \"ghp-secret-...\"}","handlingStrategy":"validation","validationCode":"// Go: pre-check for the GitHub provider\nif cfg.Provider == conf.OIDCProviderGitHub && cfg.ClientSecret == \"\" {\n\treturn errors.New(\"enter the GitHub OAuth app client secret before login\")\n}","typeGuard":"func hasGitHubSecret(cfg *conf.OIDC) bool {\n\treturn cfg == nil || cfg.Provider != conf.OIDCProviderGitHub || cfg.ClientSecret != \"\"\n}","tryCatchPattern":"// JavaScript caller\ntry {\n  await startOIDCLogin();\n} catch (e) {\n  if (e.msg.includes(\"client secret is required\")) {\n    focusField(\"oidcClientSecret\");\n  } else { throw e; }\n}","preventionTips":["Generate the GitHub OAuth app secret first, then enable GitHub login","Store secrets in the workspace config and re-enter after restores","Regenerate and update the secret whenever it is reset in GitHub","Run ValidateOIDCConfiguration after any provider switch"],"tags":["oidc","github","missing-credentials"],"backgroundTag":"missing-credentials","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}