{"record":{"id":"4f537c3b56f133ba","repo":"siyuan-note/siyuan","slug":"register-oauth-client-w","errorCode":null,"errorMessage":"register OAuth client: %w","messagePattern":"register OAuth client: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/mcp/client/oauth.go","lineNumber":307,"sourceCode":"\t\ttokenAuthMethod := preferredTokenAuthMethod(asm.TokenEndpointAuthMethodsSupported)\n\t\tif len(asm.TokenEndpointAuthMethodsSupported) > 0 && tokenAuthMethod == \"\" {\n\t\t\treturn fmt.Errorf(\"OAuth authorization server does not support a compatible token endpoint authentication method\")\n\t\t}\n\t\tgrantTypes := []string{\"authorization_code\"}\n\t\tif len(asm.GrantTypesSupported) == 0 || slices.Contains(asm.GrantTypesSupported, \"refresh_token\") {\n\t\t\tgrantTypes = append(grantTypes, \"refresh_token\")\n\t\t}\n\t\tregistration, registerErr := oauthex.RegisterClient(ctx, asm.RegistrationEndpoint, &oauthex.ClientRegistrationMetadata{\n\t\t\tRedirectURIs:            []string{callbackURL},\n\t\t\tTokenEndpointAuthMethod: tokenAuthMethod,\n\t\t\tGrantTypes:              grantTypes,\n\t\t\tResponseTypes:           []string{\"code\"},\n\t\t\tClientName:              \"SiYuan\",\n\t\t\tScope:                   strings.Join(scopes, \" \"),\n\t\t\tApplicationType:         \"native\",\n\t\t}, h.client)\n\t\tif registerErr != nil {\n\t\t\treturn fmt.Errorf(\"register OAuth client: %w\", registerErr)\n\t\t}\n\t\tregistrationCredential = oauthCredential{\n\t\t\tServerID:            h.server.ID,\n\t\t\tEndpoint:            h.server.URL,\n\t\t\tResource:            prm.Resource,\n\t\t\tIssuer:              asm.Issuer,\n\t\t\tResourceMetadataURL: prm.MetadataURL,\n\t\t\tRedirectURL:         callbackURL,\n\t\t\tClientID:            registration.ClientID,\n\t\t\tClientSecret:        registration.ClientSecret,\n\t\t\tClientSecretExpiry:  registration.ClientSecretExpiresAt,\n\t\t\tTokenEndpoint:       asm.TokenEndpoint,\n\t\t\tRevocationEndpoint:  asm.RevocationEndpoint,\n\t\t\tTokenAuthMethod:     registration.TokenEndpointAuthMethod,\n\t\t\tScopes:              scopes,\n\t\t}\n\t\tif registrationCredential.TokenAuthMethod == \"\" {\n\t\t\tif registration.ClientSecret == \"\" {","sourceCodeStart":289,"sourceCodeEnd":325,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/mcp/client/oauth.go#L289-L325","documentation":"Wraps a failure from oauthex.RegisterClient, the RFC 7591 dynamic client registration POST to asm.RegistrationEndpoint. The library wraps the underlying error so callers can distinguish registration failures from metadata, token, or consent failures during Authorize.","triggerScenarios":"Interactive Authorize reaches dynamic registration (no reusable registration, RegistrationEndpoint set, compatible auth method) and RegisterClient fails: non-2xx from the registration endpoint (400/401/403/429), invalid JSON, or a network failure.","commonSituations":"DCR endpoint requires an initial access token the client does not send; registration policy rejects the requested scopes/grant types or the loopback redirect URI; server rate-limits registrations; registration endpoint behind auth/proxy; server returns HTML error pages.","solutions":["Read the wrapped error: if it is an OAuth error response (e.g. invalid_redirect_uri, invalid_client_metadata), align the server's registration policy with the client's metadata (loopback redirect, authorization_code + refresh_token, requested scopes)","If DCR requires an initial access token, either provide one or use an IdP with open DCR","Check connectivity/auth to the registration endpoint (curl -i the URL)","Retry later if the wrapped error indicates rate limiting (429)"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"if err := h.Authorize(ctx, req, resp); err != nil {\n    if strings.Contains(err.Error(), \"register OAuth client:\") {\n        // inspect wrapped RFC 7591 error code (invalid_redirect_uri, etc.)\n        logRegistrationFailure(err)\n    }\n}","preventionTips":["Confirm the DCR endpoint accepts public native clients with loopback redirect URIs","Provide an initial access token if the registration endpoint requires one","Rate-limit repeated connect attempts to avoid DCR throttling","Ensure requested scopes are within the server's registration policy"],"tags":["oauth","mcp","dcr","http"],"backgroundTag":"oauth-token-exchange-failed","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}