{"record":{"id":"689f078518e37518","repo":"siyuan-note/siyuan","slug":"unsupported-oidc-provider-s","errorCode":null,"errorMessage":"unsupported OIDC provider [%s]","messagePattern":"unsupported OIDC provider \\[(.+?)\\]","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/oidc_provider/provider.go","lineNumber":58,"sourceCode":"\t\treturn nil, errors.New(\"OIDC client ID is required\")\n\t}\n\tif redirectURL == \"\" {\n\t\treturn nil, errors.New(\"OIDC redirect URL is required\")\n\t}\n\tif config.Provider == conf.OIDCProviderGitHub && config.ClientSecret == \"\" {\n\t\treturn nil, errors.New(\"GitHub OAuth client secret is required\")\n\t}\n\tissuerURL := strings.TrimSpace(config.IssuerURL)\n\tswitch config.Provider {\n\tcase conf.OIDCProviderGoogle:\n\t\tissuerURL = googleIssuer\n\tcase conf.OIDCProviderMicrosoft:\n\t\t// Microsoft 多租户端点的 issuer 会随租户变化，必须使用租户专属 issuer。\n\tcase conf.OIDCProviderCustom:\n\tcase conf.OIDCProviderGitHub:\n\t\treturn newGitHub(config, redirectURL), nil\n\tdefault:\n\t\treturn nil, fmt.Errorf(\"unsupported OIDC provider [%s]\", config.Provider)\n\t}\n\tif issuerURL == \"\" {\n\t\treturn nil, errors.New(\"OIDC issuer URL is required\")\n\t}\n\tdiscovered, err := oidc.NewProvider(ctx, issuerURL)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"discover OIDC provider failed: %w\", err)\n\t}\n\tscopes := append([]string{}, config.Scopes...)\n\tif !contains(scopes, oidc.ScopeOpenID) {\n\t\tscopes = append([]string{oidc.ScopeOpenID}, scopes...)\n\t}\n\treturn &Provider{\n\t\tkind: conf.OIDCProviderCustom,\n\t\toauth2Config: &oauth2.Config{\n\t\t\tClientID:     config.ClientID,\n\t\t\tClientSecret: config.ClientSecret,\n\t\t\tEndpoint:     discovered.Endpoint(),","sourceCodeStart":40,"sourceCodeEnd":76,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/oidc_provider/provider.go#L40-L76","documentation":"New switches on config.Provider to select a known issuer or GitHub-specific implementation; the default branch rejects any provider value outside the supported set (Google, Microsoft, Custom, GitHub). This guards against invalid enum values in the configuration that would otherwise lead to an undefined flow. The provider name is interpolated into the message for diagnosis.","triggerScenarios":"Calling New with config.Provider set to a string that is not one of conf.OIDCProviderGoogle / OIDCProviderMicrosoft / OIDCProviderCustom / OIDCProviderGitHub — typically from a hand-edited or partially migrated conf JSON.","commonSituations":"Upgrades where the enum constant was renamed and old persisted configs still hold the old value; admins typing provider names like \"Auth0\" or \"keycloak\" into a free-text field expecting support; config files copied from other software with different provider identifiers.","solutions":["Set config.Provider to a supported value: the constants for Google, Microsoft, GitHub, or Custom (for a generic issuer URL).","For a non-listed IdP that speaks standard OIDC discovery, use the Custom provider and set IssuerURL instead of inventing a provider name.","Inspect the persisted configuration file and correct/normalize the provider field after upgrading.","Add validation in the settings UI to restrict the field to the supported enum."],"exampleFix":"// before\ncfg := &conf.OIDC{Provider: \"auth0\", IssuerURL: \"https://xxx.auth0.com\"}\nprovider, err := New(cfg, redirectURL)\n// after\ncfg := &conf.OIDC{Provider: conf.OIDCProviderCustom, IssuerURL: \"https://xxx.auth0.com\"}\nprovider, err := New(cfg, redirectURL)","handlingStrategy":"validation","validationCode":"supported := map[string]bool{conf.OIDCProviderGoogle: true, conf.OIDCProviderMicrosoft: true, conf.OIDCProviderCustom: true, conf.OIDCProviderGitHub: true}\nif !supported[cfg.Provider] {\n    return fmt.Errorf(\"provider %q is not supported; use google, microsoft, github or custom\", cfg.Provider)\n}","typeGuard":null,"tryCatchPattern":"if err != nil {\n    if strings.Contains(err.Error(), \"unsupported OIDC provider\") {\n        // extract the provider name between [ ] and show valid options\n    }\n    return err\n}","preventionTips":["Use a dropdown/enum in the settings UI instead of free text for the provider field","Normalize provider identifiers when migrating old configs after upgrades","Reference the conf.OIDCProvider* constants, never raw string literals"],"tags":["oidc","configuration","enum","unsupported-provider"],"backgroundTag":"invalid-enum-value","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}