{"record":{"id":"733da79eb595f0c7","repo":"siyuan-note/siyuan","slug":"oidc-configuration-changed-during-provider-discove","errorCode":null,"errorMessage":"OIDC configuration changed during provider discovery","messagePattern":"OIDC configuration changed during provider discovery","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/oidc.go","lineNumber":609,"sourceCode":"\tif oidcProviders.version != version {\n\t\toidcProviders.version = version\n\t\toidcProviders.items = map[string]*oidc_provider.Provider{}\n\t}\n\tif provider := oidcProviders.items[key]; provider != nil {\n\t\toidcProviders.Unlock()\n\t\treturn provider, nil\n\t}\n\toidcProviders.Unlock()\n\tdiscoveryContext, cancel := context.WithTimeout(ctx, oidcProviderTimeout)\n\tdefer cancel()\n\tprovider, err := oidc_provider.New(discoveryContext, Conf.GetOIDC(), redirectURL)\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\toidcProviders.Lock()\n\tdefer oidcProviders.Unlock()\n\tif oidcProviders.version != version || oidcConfigurationVersion(Conf.GetOIDC()) != version {\n\t\treturn nil, errors.New(\"OIDC configuration changed during provider discovery\")\n\t}\n\tif existing := oidcProviders.items[key]; existing != nil {\n\t\treturn existing, nil\n\t}\n\tif len(oidcProviders.items) >= oidcProviderCacheMax {\n\t\toidcProviders.items = map[string]*oidc_provider.Provider{}\n\t}\n\toidcProviders.items[key] = provider\n\treturn provider, nil\n}\n\nfunc newOIDCTransaction(input *oidcStartInput, binding, clientIP, redirectURL string) (*oidcTransaction, error) {\n\tstate, err := secureRandomToken(32)\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\tnonce, err := secureRandomToken(32)\n\tif err != nil {","sourceCodeStart":591,"sourceCodeEnd":627,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/oidc.go#L591-L627","documentation":"getOIDCProvider performs OIDC provider discovery over the network and caches the result keyed by the configuration version plus redirect URL. Before storing a newly discovered provider, it re-checks that the OIDC configuration hash is still the same as when discovery started. If the configuration was modified while discovery was in flight, the stale provider is discarded and this error is thrown.","triggerScenarios":"OIDCStart or finishOIDCExchange triggers getOIDCProvider, and during the (up to oidcProviderTimeout) discovery HTTP round-trip another session/request saves a change to the OIDC settings (issuer, client ID/secret, redirect URL, etc.).","commonSituations":"An administrator edits OIDC settings while users are concurrently logging in; two overlapping configuration-save requests; automated config tooling flipping values during a login.","solutions":["Retry the OIDC login once the configuration change has settled — the new attempt will use the new configuration version","Avoid saving OIDC configuration changes while logins are in progress; apply changes during a maintenance window","If it happens repeatedly, check for clients or scripts that rewrite the config concurrently"],"exampleFix":null,"handlingStrategy":"retry","validationCode":"// Snapshot the config version before starting login and compare after any retryable failure\nversion := oidcConfigurationVersion(Conf.GetOIDC())","typeGuard":null,"tryCatchPattern":"provider, err := getOIDCProvider(ctx, redirectURL)\nif err != nil && strings.Contains(err.Error(), \"configuration changed\") {\n    time.Sleep(500 * time.Millisecond)\n    provider, err = getOIDCProvider(ctx, redirectURL) // retry with the new config version\n}","preventionTips":["Avoid saving OIDC settings while users are logging in","Batch configuration changes into a single save","Apply OIDC changes during low-traffic windows"],"tags":["oidc","race-condition","concurrency"],"backgroundTag":"invalid-state-transition","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}