{"record":{"id":"6ddb45d103b427f9","repo":"siyuan-note/siyuan","slug":"oidc-configuration-is-missing","errorCode":null,"errorMessage":"OIDC configuration is missing","messagePattern":"OIDC configuration is missing","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/oidc_provider/provider.go","lineNumber":37,"sourceCode":"\n\t\"github.com/coreos/go-oidc/v3/oidc\"\n\t\"github.com/siyuan-note/siyuan/kernel/conf\"\n\t\"golang.org/x/oauth2\"\n)\n\nconst (\n\tgoogleIssuer = \"https://accounts.google.com\"\n)\n\ntype Provider struct {\n\tkind         string\n\toauth2Config *oauth2.Config\n\tverifier     *oidc.IDTokenVerifier\n}\n\nfunc New(ctx context.Context, config *conf.OIDC, redirectURL string) (*Provider, error) {\n\tif config == nil {\n\t\treturn nil, errors.New(\"OIDC configuration is missing\")\n\t}\n\tif config.ClientID == \"\" {\n\t\treturn nil, errors.New(\"OIDC client ID is required\")\n\t}\n\tif redirectURL == \"\" {\n\t\treturn nil, errors.New(\"OIDC redirect URL is required\")\n\t}\n\tif config.Provider == conf.OIDCProviderGitHub && config.ClientSecret == \"\" {\n\t\treturn nil, errors.New(\"GitHub OAuth client secret is required\")\n\t}\n\tissuerURL := strings.TrimSpace(config.IssuerURL)\n\tswitch config.Provider {\n\tcase conf.OIDCProviderGoogle:\n\t\tissuerURL = googleIssuer\n\tcase conf.OIDCProviderMicrosoft:\n\t\t// Microsoft 多租户端点的 issuer 会随租户变化，必须使用租户专属 issuer。\n\tcase conf.OIDCProviderCustom:\n\tcase conf.OIDCProviderGitHub:","sourceCodeStart":19,"sourceCodeEnd":55,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/oidc_provider/provider.go#L19-L55","documentation":"oidc_provider.New is the constructor wrapping go-oidc/oauth2 for a configured identity provider. It validates its inputs upfront: a nil *conf.OIDC cannot yield a working provider, so it fails fast with this error. Called by OIDCValidateStart, ValidateOIDCProviderConfiguration, and getOIDCProvider.","triggerScenarios":"getOIDCProvider invoked when Conf.GetOIDC() returns nil (OIDC never configured or feature disabled); OIDCValidateStart called with no candidate config; tests pass nil intentionally (TestOIDCProviderVerifiesNonceAndPKCE exercises the non-nil path).","commonSituations":"Admin hits the OIDC login endpoint before ever saving OIDC settings; config file corrupt/reset so the OIDC section is absent; code path calls New before loading conf in early-boot flows.","solutions":["Configure OIDC in Settings - About/Auth (save client ID, secret, issuer) before starting login/validation","Check Conf.GetOIDC() returns a non-nil struct — restore/repair the workspace conf if the OIDC section is missing","Guard callers: check config presence and show 'OIDC not configured' in the UI instead of invoking the flow","In code, validate the config before calling New to get a clearer application-level error"],"exampleFix":"// before\nprovider, err := oidcprovider.New(ctx, conf.GetOIDC(), redirectURL) // nil conf\n// after\nconf := conf.GetOIDC()\nif conf == nil { return errors.New(\"OIDC is not configured\") }\nprovider, err := oidcprovider.New(ctx, conf, redirectURL)","handlingStrategy":"validation","validationCode":"conf := model.GetOIDCConfig()\nif conf == nil { show(\"OIDC login is not configured\"); return }","typeGuard":"func oidcConfigured(c *conf.OIDC) bool { return c != nil }","tryCatchPattern":"provider, err := oidcprovider.New(ctx, cfg, redirectURL)\nif err != nil && strings.Contains(err.Error(), \"configuration is missing\") {\n    return nil, fmt.Errorf(\"OIDC login is not configured; set it in Settings first\")\n}","preventionTips":["Check Conf.GetOIDC() for nil before any OIDC flow","Show 'not configured' state in the login UI when the OIDC section is absent","Run ValidateOIDCProviderConfiguration as a preflight in the settings panel"],"tags":["oidc","config","null-check","constructor"],"backgroundTag":"missing-configuration","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}