{"record":{"id":"349fc9371c1c0401","repo":"spring-projects/spring-security","slug":"unable-to-resolve-configuration-with-the-provided-349fc9","errorCode":null,"errorMessage":"Unable to resolve Configuration with the provided Issuer of \"${issuer}\", errors: ${errors}","messagePattern":"Unable to resolve Configuration with the provided Issuer of \"(.+?)\", errors: (.+?)","errorType":"exception","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/registration/ClientRegistrations.java","lineNumber":294,"sourceCode":"\t\t\ttry {\n\t\t\t\treturn supplier.get();\n\t\t\t}\n\t\t\tcatch (HttpClientErrorException ex) {\n\t\t\t\tif (!ex.getStatusCode().is4xxClientError()) {\n\t\t\t\t\tthrow ex;\n\t\t\t\t}\n\t\t\t\terrors.add(ex.getMessage());\n\t\t\t\t// else try another endpoint\n\t\t\t}\n\t\t\tcatch (IllegalArgumentException | IllegalStateException ex) {\n\t\t\t\tthrow ex;\n\t\t\t}\n\t\t\tcatch (RuntimeException ex) {\n\t\t\t\tthrow new IllegalArgumentException(errorMessage, ex);\n\t\t\t}\n\t\t}\n\t\tif (!errors.isEmpty()) {\n\t\t\tthrow new IllegalArgumentException(errorMessage + \", errors: \" + errors);\n\t\t}\n\t\tthrow new IllegalArgumentException(errorMessage);\n\t}\n\n\tprivate static <T> T parseInput(Map<String, Object> body, ThrowingFunction<JSONObject, T, ParseException> parser) {\n\t\ttry {\n\t\t\treturn parse(body, parser);\n\t\t}\n\t\tcatch (RuntimeException ex) {\n\t\t\tthrow new IllegalArgumentException(ex);\n\t\t}\n\t}\n\n\tprivate static <T> T parse(Map<String, Object> body, ThrowingFunction<JSONObject, T, ParseException> parser) {\n\t\ttry {\n\t\t\treturn parser.apply(new JSONObject(body));\n\t\t}\n\t\tcatch (ParseException ex) {","sourceCodeStart":276,"sourceCodeEnd":312,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/registration/ClientRegistrations.java#L276-L312","documentation":"Variant of the discovery failure in ClientRegistrations.getBuilder: configuration was fetched but multiple endpoints/parse attempts failed, and the collected per-endpoint errors are appended to the message ('..., errors: [...]') to explain why resolution failed.","triggerScenarios":"fromIssuerLocation(issuer) trying both openid-configuration and oauth-authorization-server URLs; both attempts fail with runtime exceptions whose messages are accumulated into the errors list, producing this richer IllegalArgumentException.","commonSituations":"Discovery endpoint returns 200 but with HTML (login page/redirect) instead of JSON; server returns malformed JSON; intermittent upstream 500s recorded per attempt; misconfigured reverse proxy.","solutions":["Read the appended errors list — it names each endpoint's underlying failure (status, parse exception) and fix that root cause first.","curl the discovery URLs and confirm they return valid JSON (an HTML login page means auth/redirect is intercepting the request).","Whitelist/exempt the discovery path from gateway authentication, or supply a cookie/proxy config so the request reaches the metadata handler.","Fall back to a manually built ClientRegistration if discovery cannot be repaired on the provider side."],"exampleFix":"// before\nClientRegistrations.fromIssuerLocation(\"https://idp\"); // gateway returns HTML login page -> parse errors\n// after\n// allowlist /.well-known/* on the gateway, then retry:\nClientRegistrations.fromIssuerLocation(\"https://idp\");","handlingStrategy":"try-catch","validationCode":"// fetch and JSON-parse discovery yourself to surface the real error\nString body = rest.getForEntity(issuer + \"/.well-known/openid-configuration\", String.class).getBody();\nnew com.fasterxml.jackson.databind.ObjectMapper().readTree(body); // throws with a precise parse error","typeGuard":null,"tryCatchPattern":"try { ClientRegistrations.fromIssuerLocation(issuer); } catch (IllegalArgumentException e) { log.error(\"Discovery failed: {}\", e.getMessage(), e); /* inspect ', errors:' appendix */ throw e; }","preventionTips":["Check the ', errors:' suffix in the message for per-endpoint root causes","Ensure discovery URLs return application/json (no HTML login/redirect pages)","Warm up discovery during deployment health checks"],"tags":["oauth2","oidc","discovery","network","json"],"backgroundTag":"invalid-json-response","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}