{"record":{"id":"e019986bd78b5946","repo":"siyuan-note/siyuan","slug":"github-oauth-client-secret-is-required-e01998","errorCode":null,"errorMessage":"GitHub OAuth client secret is required","messagePattern":"GitHub OAuth client secret is required","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/oidc_provider/provider.go","lineNumber":46,"sourceCode":"\ntype Provider struct {\n\tkind         string\n\toauth2Config *oauth2.Config\n\tverifier     *oidc.IDTokenVerifier\n}\n\nfunc New(ctx context.Context, config *conf.OIDC, redirectURL string) (*Provider, error) {\n\tif config == nil {\n\t\treturn nil, errors.New(\"OIDC configuration is missing\")\n\t}\n\tif config.ClientID == \"\" {\n\t\treturn nil, errors.New(\"OIDC client ID is required\")\n\t}\n\tif redirectURL == \"\" {\n\t\treturn nil, errors.New(\"OIDC redirect URL is required\")\n\t}\n\tif config.Provider == conf.OIDCProviderGitHub && config.ClientSecret == \"\" {\n\t\treturn nil, errors.New(\"GitHub OAuth client secret is required\")\n\t}\n\tissuerURL := strings.TrimSpace(config.IssuerURL)\n\tswitch config.Provider {\n\tcase conf.OIDCProviderGoogle:\n\t\tissuerURL = googleIssuer\n\tcase conf.OIDCProviderMicrosoft:\n\t\t// Microsoft 多租户端点的 issuer 会随租户变化，必须使用租户专属 issuer。\n\tcase conf.OIDCProviderCustom:\n\tcase conf.OIDCProviderGitHub:\n\t\treturn newGitHub(config, redirectURL), nil\n\tdefault:\n\t\treturn nil, fmt.Errorf(\"unsupported OIDC provider [%s]\", config.Provider)\n\t}\n\tif issuerURL == \"\" {\n\t\treturn nil, errors.New(\"OIDC issuer URL is required\")\n\t}\n\tdiscovered, err := oidc.NewProvider(ctx, issuerURL)\n\tif err != nil {","sourceCodeStart":28,"sourceCodeEnd":64,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/oidc_provider/provider.go#L28-L64","documentation":"New refuses to construct a GitHub OIDC/OAuth provider when config.Provider is conf.OIDCProviderGitHub and config.ClientSecret is empty. GitHub's OAuth app flow requires the client secret during the token exchange, so a Provider without one can never complete sign-in. The error is raised eagerly at provider construction to surface the misconfiguration immediately.","triggerScenarios":"Calling New with config.Provider == conf.OIDCProviderGitHub and config.ClientSecret == \"\" — e.g. the admin created the GitHub OAuth app but never copied the secret into the SiYuan OIDC settings.","commonSituations":"Admin pasted only the client ID from GitHub; the secret was rotated/revoked and cleared from config; config was copied between environments (staging to production) with the secret redacted; storing the secret in an env var that is unset in the deployment.","solutions":["Enter the GitHub OAuth app's Client Secret in the OIDC settings and save.","If the secret is injected from the environment, verify the env var is set in the process environment before the kernel starts.","Create a new OAuth App on GitHub (Developer settings) and copy the secret if the old one was lost or revoked.","Restart the sign-in flow after saving so New is called with the complete config."],"exampleFix":"// before\ncfg := &conf.OIDC{Provider: conf.OIDCProviderGitHub, ClientID: \"Iv1.xxxx\"} // no secret\nprovider, err := New(cfg, redirectURL)\n// after\ncfg := &conf.OIDC{Provider: conf.OIDCProviderGitHub, ClientID: \"Iv1.xxxx\", ClientSecret: os.Getenv(\"GITHUB_CLIENT_SECRET\")}\nif cfg.ClientSecret == \"\" {\n    return errors.New(\"GITHUB_CLIENT_SECRET is not set\")\n}\nprovider, err := New(cfg, redirectURL)","handlingStrategy":"validation","validationCode":"if cfg.Provider == conf.OIDCProviderGitHub && strings.TrimSpace(cfg.ClientSecret) == \"\" {\n    return errors.New(\"GitHub client secret must be set in OIDC settings\")\n}","typeGuard":null,"tryCatchPattern":"if err != nil {\n    if strings.Contains(err.Error(), \"client secret is required\") {\n        // prompt the admin to enter the GitHub OAuth app secret\n    }\n    return err\n}","preventionTips":["Store the client secret in an environment variable or secret store, never in the repo","Validate all provider-specific required fields when saving the OIDC configuration","Rotate secrets through a documented process so the config is never left blank"],"tags":["oidc","oauth2","github","credentials","configuration"],"backgroundTag":"missing-credentials","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}