{"record":{"id":"98fe778fff5b84ca","repo":"siyuan-note/siyuan","slug":"unsupported-oidc-provider","errorCode":null,"errorMessage":"Unsupported OIDC provider","messagePattern":"Unsupported OIDC provider","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/oidc.go","lineNumber":477,"sourceCode":"\tif config.ClientID == \"\" {\n\t\treturn errors.New(\"OIDC client ID is required\")\n\t}\n\tif config.Provider == conf.OIDCProviderGitHub && config.ClientSecret == \"\" {\n\t\treturn errors.New(\"GitHub OAuth client secret is required\")\n\t}\n\tif (config.Provider == conf.OIDCProviderCustom || config.Provider == conf.OIDCProviderMicrosoft) && config.IssuerURL == \"\" {\n\t\treturn errors.New(\"OIDC issuer URL is required\")\n\t}\n\tif (config.Provider == conf.OIDCProviderCustom || config.Provider == conf.OIDCProviderMicrosoft) && config.IssuerURL != \"\" {\n\t\tissuer, err := url.Parse(config.IssuerURL)\n\t\tif err != nil || issuer.Host == \"\" || issuer.User != nil || issuer.RawQuery != \"\" || issuer.Fragment != \"\" ||\n\t\t\t(issuer.Scheme != \"https\" && !util.IsLocalHostname(issuer.Hostname())) {\n\t\t\treturn errors.New(\"OIDC issuer URL must use HTTPS unless it is a loopback address\")\n\t\t}\n\t}\n\tif config.Provider != conf.OIDCProviderCustom && config.Provider != conf.OIDCProviderGoogle &&\n\t\tconfig.Provider != conf.OIDCProviderMicrosoft && config.Provider != conf.OIDCProviderGitHub {\n\t\treturn errors.New(\"Unsupported OIDC provider\")\n\t}\n\tif !config.AllowAll && len(config.ClaimRules) == 0 {\n\t\treturn errors.New(\"OIDC login requires at least one claim rule when Allow all users is disabled\")\n\t}\n\tfor _, rule := range config.ClaimRules {\n\t\tif rule == nil || rule.Claim == \"\" || len(rule.Values) == 0 {\n\t\t\treturn errors.New(\"OIDC claim rules must include a claim and at least one value\")\n\t\t}\n\t\tif rule.Operator != conf.OIDCClaimOperatorEquals && rule.Operator != conf.OIDCClaimOperatorContains {\n\t\t\treturn errors.New(\"Unsupported OIDC claim rule operator\")\n\t\t}\n\t\tfor _, value := range rule.Values {\n\t\t\tif value == \"\" {\n\t\t\t\treturn errors.New(\"OIDC claim rule values cannot be empty\")\n\t\t\t}\n\t\t}\n\t}\n\treturn nil","sourceCodeStart":459,"sourceCodeEnd":495,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/oidc.go#L459-L495","documentation":"ValidateOIDCConfiguration only accepts the four known providers: custom, Google, Microsoft, and GitHub. If config.Provider holds any other value (unknown string, empty, or an invalid enum), validation stops with \"Unsupported OIDC provider\". This guards against typos and misconfigured deployments before the OAuth flow starts.","triggerScenarios":"Calling ValidateOIDCConfiguration with config.Provider not equal to OIDCProviderCustom, OIDCProviderGoogle, OIDCProviderMicrosoft, or OIDCProviderGitHub — e.g. an empty provider field, a hand-edited config value, or a config file from an older/newer schema.","commonSituations":"Hand-editing workspace conf.json and mistyping the provider name; restoring a config where the provider field was blank; a script writing an arbitrary provider string; switching providers and clearing the field instead of selecting one.","solutions":["Set the provider to one of the supported values (custom, google, microsoft, github) in Settings - Accounts - OIDC.","If hand-editing the config, use the exact provider identifiers accepted by conf.OIDC constants.","Re-select the provider in the UI and save so the value is validated before use.","Check for schema drift if the config came from an old version and re-apply settings."],"exampleFix":"// before\n{\"oidc\": {\"enabled\": true, \"provider\": \"okta\"}}\n// after\n{\"oidc\": {\"enabled\": true, \"provider\": \"custom\", \"issuerURL\": \"https://your-org.okta.com\"}}","handlingStrategy":"validation","validationCode":"// Go: restrict provider values before saving/validating\nswitch cfg.Provider {\ncase conf.OIDCProviderCustom, conf.OIDCProviderGoogle,\n\tconf.OIDCProviderMicrosoft, conf.OIDCProviderGitHub:\n\t// ok\ndefault:\n\treturn errors.New(\"provider must be custom, google, microsoft, or github\")\n}","typeGuard":"func knownProvider(p string) bool {\n\tswitch p {\n\tcase conf.OIDCProviderCustom, conf.OIDCProviderGoogle,\n\t\tconf.OIDCProviderMicrosoft, conf.OIDCProviderGitHub:\n\t\treturn true\n\t}\n\treturn false\n}","tryCatchPattern":"// JavaScript caller\ntry {\n  await saveOIDCSettings(cfg);\n} catch (e) {\n  if (e.msg.includes(\"Unsupported OIDC provider\")) {\n    resetProviderSelection(); // force choosing from the supported list\n  } else { throw e; }\n}","preventionTips":["Always pick the provider from the UI dropdown instead of hand-editing config","Treat the provider string as an enum; validate on write","Map third-party IdPs (Okta, Auth0, Keycloak) to the custom provider, never custom strings","Re-validate the config after restoring or migrating workspace conf.json"],"tags":["oidc","configuration","enum"],"backgroundTag":"invalid-enum-value","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}