{"record":{"id":"789ce9167be8e57a","repo":"siyuan-note/siyuan","slug":"discover-oidc-provider-failed-w","errorCode":null,"errorMessage":"discover OIDC provider failed: %w","messagePattern":"discover OIDC provider failed: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/oidc_provider/provider.go","lineNumber":65,"sourceCode":"\t}\n\tissuerURL := strings.TrimSpace(config.IssuerURL)\n\tswitch config.Provider {\n\tcase conf.OIDCProviderGoogle:\n\t\tissuerURL = googleIssuer\n\tcase conf.OIDCProviderMicrosoft:\n\t\t// Microsoft 多租户端点的 issuer 会随租户变化，必须使用租户专属 issuer。\n\tcase conf.OIDCProviderCustom:\n\tcase conf.OIDCProviderGitHub:\n\t\treturn newGitHub(config, redirectURL), nil\n\tdefault:\n\t\treturn nil, fmt.Errorf(\"unsupported OIDC provider [%s]\", config.Provider)\n\t}\n\tif issuerURL == \"\" {\n\t\treturn nil, errors.New(\"OIDC issuer URL is required\")\n\t}\n\tdiscovered, err := oidc.NewProvider(ctx, issuerURL)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"discover OIDC provider failed: %w\", err)\n\t}\n\tscopes := append([]string{}, config.Scopes...)\n\tif !contains(scopes, oidc.ScopeOpenID) {\n\t\tscopes = append([]string{oidc.ScopeOpenID}, scopes...)\n\t}\n\treturn &Provider{\n\t\tkind: conf.OIDCProviderCustom,\n\t\toauth2Config: &oauth2.Config{\n\t\t\tClientID:     config.ClientID,\n\t\t\tClientSecret: config.ClientSecret,\n\t\t\tEndpoint:     discovered.Endpoint(),\n\t\t\tRedirectURL:  redirectURL,\n\t\t\tScopes:       scopes,\n\t\t},\n\t\tverifier: discovered.Verifier(&oidc.Config{ClientID: config.ClientID}),\n\t}, nil\n}\n","sourceCodeStart":47,"sourceCodeEnd":83,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/oidc_provider/provider.go#L47-L83","documentation":"New performs OIDC discovery by fetching {issuerURL}/.well-known/openid-configuration via go-oidc's oidc.NewProvider; any failure (DNS, TLS, HTTP status, malformed discovery document) is wrapped as \"discover OIDC provider failed\" with the underlying error. This means the kernel could not retrieve or parse the IdP's discovery metadata, so the OIDC endpoints and keys are unknown.","triggerScenarios":"Calling New where oidc.NewProvider(ctx, issuerURL) fails: issuer URL typo, IdP unreachable, self-signed/expired TLS certificate, discovery endpoint returning non-200, or a document missing required fields (e.g. no jwks_uri).","commonSituations":"Self-hosted Keycloak/Auth0/Dex behind a firewall or VPN the kernel cannot reach; internal CA certificates not trusted by the container; wrong realm or tenant in the issuer path; IdP serving discovery only on a different external URL; DNS or proxy misconfiguration in Docker/Kubernetes.","solutions":["Verify the issuer URL is exactly what the IdP advertises (check https://<issuer>/.well-known/openid-configuration loads and matches the issuer claim).","Confirm network reachability from the kernel host: curl the discovery URL from the same machine/container.","Fix TLS trust: install the internal CA into the system trust store or provide proper certificates; check for expired certs.","Check proxy/DNS settings for the kernel process and retry after the IdP (or its outage) is restored.","Read the wrapped cause after the colon in the message to identify DNS vs TLS vs HTTP vs parse failure."],"exampleFix":"// before\ncfg := &conf.OIDC{Provider: conf.OIDCProviderCustom, IssuerURL: \"https://sso.internal/keycloak\"} // wrong path, discovery 404s\nprovider, err := New(cfg, redirectURL)\n// after\ncfg := &conf.OIDC{Provider: conf.OIDCProviderCustom, IssuerURL: \"https://sso.internal/realms/main\"} // matches .well-known/openid-configuration location\nprovider, err := New(cfg, redirectURL)","handlingStrategy":"retry","validationCode":"resp, err := http.Get(strings.TrimSuffix(issuerURL, \"/\") + \"/.well-known/openid-configuration\")\nif err != nil || resp.StatusCode != http.StatusOK {\n    return errors.New(\"issuer discovery endpoint is not reachable from this host\")\n}","typeGuard":null,"tryCatchPattern":"provider, err := New(cfg, redirectURL)\nif err != nil {\n    if strings.Contains(err.Error(), \"discover OIDC provider failed\") {\n        // retry with backoff for transient network issues; otherwise surface the wrapped cause\n    }\n    return err\n}","preventionTips":["Curl the discovery URL from the kernel host before configuring the provider","Install internal CA certificates into containers using the kernel","Keep NTP synchronized and verify the issuer URL matches the IdP's advertised issuer exactly","Document firewall/proxy requirements for the token and discovery endpoints"],"tags":["oidc","network","discovery","http","tls"],"backgroundTag":"http-error-response","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}