{"record":{"id":"9148b9d7c6c5b7fc","repo":"siyuan-note/siyuan","slug":"remote-access-requires-at-least-one-authentication","errorCode":null,"errorMessage":"remote access requires at least one authentication method","messagePattern":"remote access requires at least one authentication method","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"kernel/model/oidc.go","lineNumber":529,"sourceCode":"\t}\n\tredirectURL := \"http://127.0.0.1:6806/api/system/oidc/callback\"\n\tif config.RedirectURL != \"\" {\n\t\tvar err error\n\t\tif redirectURL, err = validatePublicOIDCRedirectURL(config.RedirectURL); err != nil {\n\t\t\treturn err\n\t\t}\n\t}\n\tvalidationContext, cancel := context.WithTimeout(ctx, oidcProviderTimeout)\n\tdefer cancel()\n\t_, err := oidc_provider.New(validationContext, config, redirectURL)\n\treturn err\n}\n\nfunc ValidateOIDCConfigurationChange(ctx context.Context, config *conf.OIDC, requireRemoteRedirect,\n\thasAlternativeAuthentication, bypassAuthentication bool) error {\n\tif config == nil || !config.Enabled {\n\t\tif requireRemoteRedirect && !hasAlternativeAuthentication && !bypassAuthentication {\n\t\t\treturn errors.New(\"remote access requires at least one authentication method\")\n\t\t}\n\t\treturn nil\n\t}\n\tif requireRemoteRedirect {\n\t\tif _, err := validatePublicOIDCRedirectURL(config.RedirectURL); err != nil {\n\t\t\treturn err\n\t\t}\n\t}\n\treturn ValidateOIDCProviderConfiguration(ctx, config)\n}\n\nfunc effectiveOIDCRedirectURL(c *gin.Context, flow string) (string, error) {\n\tif flow == oidcFlowMobile {\n\t\treturn oidcMobileRedirectURL, nil\n\t}\n\tif flow == oidcFlowWeb && !IsLocalRequest(c) {\n\t\treturn validatePublicOIDCRedirectURL(Conf.GetOIDC().RedirectURL)\n\t}","sourceCodeStart":511,"sourceCodeEnd":547,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/oidc.go#L511-L547","documentation":"ValidateOIDCConfigurationChange prevents remote lockout: when the incoming request requires remote redirection and no authentication method remains available (OIDC disabled/absent, no alternative authentication, and no auth bypass), the change is rejected so a remote administrator cannot cut off their own access.","triggerScenarios":"Calling ValidateOIDCConfigurationChange with (config == nil || !config.Enabled) == true, requireRemoteRedirect == true, hasAlternativeAuthentication == false, bypassAuthentication == false; also fired from InitConf and OIDCValidateStart under the same conditions.","commonSituations":"Admin accessing SiYuan over a public URL tries to disable OIDC (or the whole auth config fails validation) while no local session/password auth fallback exists; remote setup without any other login method.","solutions":["Enable an alternative authentication method (e.g. access auth password) before disabling OIDC","Keep the OIDC configuration valid and Enabled when accessing remotely","Perform the change from a local (loopback) session where requireRemoteRedirect is false","Use bypassAuthentication only if you understand it grants unauthenticated access"],"exampleFix":"// before\nValidateOIDCConfigurationChange(ctx, nil, true, false, false)\n// after\nValidateOIDCConfigurationChange(ctx, nil, true, true, false) // alternative auth available","handlingStrategy":"validation","validationCode":"// before disabling OIDC remotely, ensure a fallback exists:\nif (remoteAccess && !oidcEnabled && !hasAlternativeAuth) throw new Error('would lock out remote access');","typeGuard":null,"tryCatchPattern":"if err := ValidateOIDCConfigurationChange(ctx, cfg, requireRemote, hasAlt, bypass); err != nil {\n    log.Printf(\"config change rejected to prevent lockout: %v\", err)\n    // retry from a local session or enable alternative auth first\n}","preventionTips":["Always keep a working local session available when changing auth config","Enable access-auth password before disabling OIDC on remote deployments","Perform auth-configuration changes from loopback, not through a public URL"],"tags":["oidc","lockout","auth","config"],"backgroundTag":"conflicting-config-options","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}