{"record":{"id":"c8c296664dadecb8","repo":"siyuan-note/siyuan","slug":"google-does-not-support-the-fixed-siyuan-mobile-oi","errorCode":null,"errorMessage":"Google does not support the fixed SiYuan mobile OIDC callback URI","messagePattern":"Google does not support the fixed SiYuan mobile OIDC callback URI","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/oidc.go","lineNumber":503,"sourceCode":"\t\t}\n\t\tif rule.Operator != conf.OIDCClaimOperatorEquals && rule.Operator != conf.OIDCClaimOperatorContains {\n\t\t\treturn errors.New(\"Unsupported OIDC claim rule operator\")\n\t\t}\n\t\tfor _, value := range rule.Values {\n\t\t\tif value == \"\" {\n\t\t\t\treturn errors.New(\"OIDC claim rule values cannot be empty\")\n\t\t\t}\n\t\t}\n\t}\n\treturn nil\n}\n\nfunc ValidateOIDCMobileConfiguration(config *conf.OIDC) error {\n\tif err := ValidateOIDCConfiguration(config); err != nil {\n\t\treturn err\n\t}\n\tif config.Provider == conf.OIDCProviderGoogle {\n\t\treturn errors.New(\"Google does not support the fixed SiYuan mobile OIDC callback URI\")\n\t}\n\treturn nil\n}\n\nfunc ValidateOIDCProviderConfiguration(ctx context.Context, config *conf.OIDC) error {\n\tif err := ValidateOIDCConfiguration(config); err != nil {\n\t\treturn err\n\t}\n\tredirectURL := \"http://127.0.0.1:6806/api/system/oidc/callback\"\n\tif config.RedirectURL != \"\" {\n\t\tvar err error\n\t\tif redirectURL, err = validatePublicOIDCRedirectURL(config.RedirectURL); err != nil {\n\t\t\treturn err\n\t\t}\n\t}\n\tvalidationContext, cancel := context.WithTimeout(ctx, oidcProviderTimeout)\n\tdefer cancel()\n\t_, err := oidc_provider.New(validationContext, config, redirectURL)","sourceCodeStart":485,"sourceCodeEnd":521,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/oidc.go#L485-L521","documentation":"The SiYuan mobile app uses a fixed OIDC redirect URI that cannot be registered per-tenant with Google, so ValidateOIDCMobileConfiguration rejects Google as the mobile OIDC provider. Google's redirect URI restrictions conflict with the hard-coded callback the app presents.","triggerScenarios":"Calling ValidateOIDCMobileConfiguration with config.Provider == conf.OIDCProviderGoogle after the general validation passes.","commonSituations":"Admin selects Google in the mobile OIDC provider settings; an API client reuses a Google desktop config for the mobile flow.","solutions":["Choose a custom OIDC provider that allows arbitrary redirect URIs for mobile login","Use Microsoft or GitHub, whose redirect handling is compatible with the fixed callback","Restrict Google SSO to the desktop flow, where a loopback redirect is used"],"exampleFix":"// before\nconfig.Provider = conf.OIDCProviderGoogle\nreturn ValidateOIDCMobileConfiguration(config)\n// after\nconfig.Provider = conf.OIDCProviderCustom\nreturn ValidateOIDCMobileConfiguration(config)","handlingStrategy":"validation","validationCode":"const mobileUnsupported = ['google'];\nif (mobile && mobileUnsupported.includes(config.provider)) { alert('Provider not supported for mobile OIDC'); }","typeGuard":null,"tryCatchPattern":"if err := ValidateOIDCMobileConfiguration(cfg); err != nil {\n    if strings.Contains(err.Error(), \"Google does not support\") { /* fall back to custom provider */ }\n}","preventionTips":["Filter the mobile provider picker to supported providers only","Reuse desktop Google configs only for the desktop flow","Document the fixed mobile callback URI limitation"],"tags":["oidc","mobile","provider"],"backgroundTag":"unsupported-operation","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}