{"record":{"id":"6cbecec05d12ff6d","repo":"siyuan-note/siyuan","slug":"oauth-authorization-failed-s","errorCode":null,"errorMessage":"OAuth authorization failed: %s","messagePattern":"OAuth authorization failed: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/mcp/client/oauth.go","lineNumber":386,"sourceCode":"\t}\n\toauthFlows.Lock()\n\toauthFlows.items[flowID] = flow\n\toauthFlows.Unlock()\n\tdefer removeOAuthFlow(flowID, flow)\n\tsetMCPRuntimeStateForContext(ctx, h.server.ID, \"authorizing\", 0, \"\", authorizationURL)\n\n\tvar callback oauthCallbackResult\n\ttimer := time.NewTimer(oauthAuthorizationTimeout)\n\tdefer timer.Stop()\n\tselect {\n\tcase callback = <-flow.Result:\n\tcase <-ctx.Done():\n\t\treturn ctx.Err()\n\tcase <-timer.C:\n\t\treturn fmt.Errorf(\"OAuth authorization timed out\")\n\t}\n\tif callback.Error != \"\" {\n\t\treturn fmt.Errorf(\"OAuth authorization failed: %s\", callback.Error)\n\t}\n\tif callback.State != state {\n\t\treturn fmt.Errorf(\"OAuth state mismatch\")\n\t}\n\tif callback.Code == \"\" {\n\t\treturn fmt.Errorf(\"OAuth callback did not include an authorization code\")\n\t}\n\n\texchangeCtx := context.WithValue(ctx, oauth2.HTTPClient, h.client)\n\ttoken, err := config.Exchange(exchangeCtx, callback.Code,\n\t\toauth2.VerifierOption(verifier),\n\t\toauth2.SetAuthURLParam(\"resource\", prm.Resource))\n\tif err != nil {\n\t\treturn fmt.Errorf(\"exchange OAuth authorization code: %w\", err)\n\t}\n\tif token.TokenType != \"\" && !strings.EqualFold(token.TokenType, \"Bearer\") {\n\t\treturn fmt.Errorf(\"OAuth token endpoint returned unsupported token type %q\", token.TokenType)\n\t}","sourceCodeStart":368,"sourceCodeEnd":404,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/mcp/client/oauth.go#L368-L404","documentation":"The OAuth redirect back to the local callback endpoint may carry an error parameter (per RFC 6749 section 4.1.2.1, e.g. access_denied, invalid_scope). When the browser callback reports such an error, the flow surfaces it verbatim as 'OAuth authorization failed: <server error>'.","triggerScenarios":"User completes the authorization redirect but the IdP redirected to the callback with error=... (plus optional error_description), e.g. after the user denied consent or the request was rejected (invalid_scope, access_denied, server_error).","commonSituations":"User clicked 'Deny'/'Cancel' on the consent screen; the requested scopes are not grantable for this client; the IdP rejected PKCE or the resource parameter; account restrictions on the chosen user.","solutions":["Read the error text after the colon to identify the IdP's reason (e.g. access_denied, invalid_scope)","Retry and approve the consent request in the browser","If invalid_scope, align the server's advertised scopes with what the client requests, or grant the client those scopes","If the IdP rejects PKCE or the resource parameter, update/fix the authorization server configuration"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"// Pre-check that requested scopes are within what the resource metadata advertises\nfor _, s := range requestedScopes {\n    if !slices.Contains(prm.ScopesSupported, s) { /* scope will likely be denied */ }\n}","typeGuard":null,"tryCatchPattern":"if err := h.Authorize(ctx, true); err != nil {\n    if strings.HasPrefix(err.Error(), \"OAuth authorization failed:\") {\n        idpErr := strings.TrimPrefix(err.Error(), \"OAuth authorization failed: \")\n        // branch on access_denied / invalid_scope etc.\n    }\n}","preventionTips":["Instruct users to approve the consent screen rather than cancel it","Ensure requested scopes match the server's supported scopes","Verify the client is allowed the requested scopes in the IdP's client configuration"],"tags":["oauth","mcp","authorization-denied","rfc6749"],"backgroundTag":"oauth-token-exchange-failed","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}