{"record":{"id":"40d185bb4cb12da1","repo":"siyuan-note/siyuan","slug":"public-oidc-redirect-url-must-use-https","errorCode":null,"errorMessage":"Public OIDC redirect URL must use HTTPS","messagePattern":"Public OIDC redirect URL must use HTTPS","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/oidc.go","lineNumber":582,"sourceCode":"\t\treturn oidcMobileRedirectURL, nil\n\t}\n\tif config.RedirectURL != \"\" {\n\t\treturn validatePublicOIDCRedirectURL(config.RedirectURL)\n\t}\n\treturn effectiveOIDCRedirectURL(c, oidcFlowDesktop)\n}\n\nfunc validatePublicOIDCRedirectURL(redirectURL string) (string, error) {\n\tif redirectURL == \"\" {\n\t\treturn \"\", errors.New(\"A public HTTPS OIDC redirect URL is required for remote access\")\n\t}\n\tparsed, err := url.Parse(redirectURL)\n\tif err != nil || parsed.Scheme == \"\" || parsed.Host == \"\" || parsed.Path != \"/api/system/oidc/callback\" ||\n\t\tparsed.User != nil || parsed.RawQuery != \"\" || parsed.Fragment != \"\" {\n\t\treturn \"\", errors.New(\"OIDC redirect URL must end with /api/system/oidc/callback\")\n\t}\n\tif parsed.Scheme != \"https\" {\n\t\treturn \"\", errors.New(\"Public OIDC redirect URL must use HTTPS\")\n\t}\n\treturn parsed.String(), nil\n}\n\nfunc getOIDCProvider(ctx context.Context, redirectURL string) (*oidc_provider.Provider, error) {\n\tversion := oidcConfigurationVersion(Conf.GetOIDC())\n\tkey := version + \"\\x00\" + redirectURL\n\toidcProviders.Lock()\n\tif oidcProviders.version != version {\n\t\toidcProviders.version = version\n\t\toidcProviders.items = map[string]*oidc_provider.Provider{}\n\t}\n\tif provider := oidcProviders.items[key]; provider != nil {\n\t\toidcProviders.Unlock()\n\t\treturn provider, nil\n\t}\n\toidcProviders.Unlock()\n\tdiscoveryContext, cancel := context.WithTimeout(ctx, oidcProviderTimeout)","sourceCodeStart":564,"sourceCodeEnd":600,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/oidc.go#L564-L600","documentation":"validatePublicOIDCRedirectURL parses the configured OIDC redirect URL and requires that it be an absolute https URL ending exactly with /api/system/oidc/callback, with no userinfo, query, or fragment. This error is thrown when the URL passes the shape check but its scheme is not https. SiYuan enforces HTTPS for publicly configured redirect URLs because the OIDC authorization code would otherwise traverse the network unencrypted.","triggerScenarios":"Calling ValidateOIDCProviderConfiguration, ValidateOIDCConfigurationChange, or starting/validating an OIDC login while conf.OIDC.RedirectURL is set to an http:// URL (e.g. http://example.com/api/system/oidc/callback).","commonSituations":"Self-hosted setups behind a reverse proxy that terminates TLS but leave the internal redirect URL on http://; users testing on localhost with plain http; configuration copied from an HTTP-only deployment.","solutions":["Change the configured OIDC redirect URL to use https:// (e.g. https://your-domain/api/system/oidc/callback) in Settings - OIDC or conf.OIDC.RedirectURL","Set up TLS termination (reverse proxy with a certificate) so the callback endpoint is reachable over HTTPS","If this is purely a local desktop flow, clear the custom RedirectURL so the kernel generates the loopback redirect URL instead"],"exampleFix":"// before\nConf.GetOIDC().RedirectURL = \"http://siyuan.example.com/api/system/oidc/callback\"\n// after\nConf.GetOIDC().RedirectURL = \"https://siyuan.example.com/api/system/oidc/callback\"","handlingStrategy":"validation","validationCode":"u, err := url.Parse(redirectURL)\nif err != nil || u.Scheme != \"https\" || u.Path != \"/api/system/oidc/callback\" || u.RawQuery != \"\" || u.Fragment != \"\" || u.User != nil {\n    return errors.New(\"redirect URL must be https and end with /api/system/oidc/callback\")\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always configure the OIDC redirect URL with https:// for remote/public access","Terminate TLS at a reverse proxy and keep the public URL scheme https","Test the configuration via the built-in OIDC validation before saving"],"tags":["oidc","https","config-validation"],"backgroundTag":"invalid-config-value","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}