{"record":{"id":"e411054d9b316980","repo":"siyuan-note/siyuan","slug":"oidc-login-is-not-enabled","errorCode":null,"errorMessage":"OIDC login is not enabled","messagePattern":"OIDC login is not enabled","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/oidc.go","lineNumber":457,"sourceCode":"\tinput := request\n\tif err := request.ParseError(); err != nil || input.PollToken == \"\" {\n\t\tret = apicontract.Failure[apicontract.Null](-1, oidcLanguage(369, \"Invalid OIDC configuration\"))\n\t\treturn\n\t}\n\tworkspaceSession := util.GetWorkspaceSession(util.GetSession(c))\n\tif !cancelOIDCValidation(input.PollToken, workspaceSession.OIDCBinding) {\n\t\tret = apicontract.Failure[apicontract.Null](-1, oidcLanguage(369, \"Invalid OIDC configuration\"))\n\t}\n\treturn\n}\n\nfunc validateOIDCConfiguration() error {\n\treturn ValidateOIDCConfiguration(Conf.GetOIDC())\n}\n\nfunc ValidateOIDCConfiguration(config *conf.OIDC) error {\n\tif config == nil || !config.Enabled {\n\t\treturn errors.New(\"OIDC login is not enabled\")\n\t}\n\tif config.ClientID == \"\" {\n\t\treturn errors.New(\"OIDC client ID is required\")\n\t}\n\tif config.Provider == conf.OIDCProviderGitHub && config.ClientSecret == \"\" {\n\t\treturn errors.New(\"GitHub OAuth client secret is required\")\n\t}\n\tif (config.Provider == conf.OIDCProviderCustom || config.Provider == conf.OIDCProviderMicrosoft) && config.IssuerURL == \"\" {\n\t\treturn errors.New(\"OIDC issuer URL is required\")\n\t}\n\tif (config.Provider == conf.OIDCProviderCustom || config.Provider == conf.OIDCProviderMicrosoft) && config.IssuerURL != \"\" {\n\t\tissuer, err := url.Parse(config.IssuerURL)\n\t\tif err != nil || issuer.Host == \"\" || issuer.User != nil || issuer.RawQuery != \"\" || issuer.Fragment != \"\" ||\n\t\t\t(issuer.Scheme != \"https\" && !util.IsLocalHostname(issuer.Hostname())) {\n\t\t\treturn errors.New(\"OIDC issuer URL must use HTTPS unless it is a loopback address\")\n\t\t}\n\t}\n\tif config.Provider != conf.OIDCProviderCustom && config.Provider != conf.OIDCProviderGoogle &&","sourceCodeStart":439,"sourceCodeEnd":475,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/oidc.go#L439-L475","documentation":"ValidateOIDCConfiguration checks the OIDC login configuration before any authentication flow runs. The first gate requires a non-nil config with Enabled=true. When OIDC is disabled (or the config object is missing entirely), any attempt to use or validate OIDC login returns \"OIDC login is not enabled\".","triggerScenarios":"Calling validateOIDCConfiguration (and thus any login flow depending on it) while Conf.GetOIDC() returns nil or a config with Enabled=false; invoking ValidateOIDCConfiguration/ValidateOIDCMobileConfiguration with an OIDC config whose enabled toggle is off; tests calling it with a default/unset config.","commonSituations":"Upgrading SiYuan and forgetting to re-enable OIDC after config reset; setting the provider fields but not flipping the enable switch; a fresh install where the OIDC section was never configured; mobile login pointing at a workspace with OIDC off.","solutions":["Enable OIDC in Settings - About (or set the enabled field of the OIDC config to true) and retry login.","If the config is nil, configure the OIDC section completely before enabling it.","Check workspace config/conf.json to confirm the oidc.enabled value persisted after restart.","For programmatic use, enable the provider in the caller (e.g. the admin panel) before invoking OIDC login endpoints."],"exampleFix":"// before\n{\"oidc\": {\"enabled\": false, \"clientID\": \"my-app\"}}\n// after\n{\"oidc\": {\"enabled\": true, \"clientID\": \"my-app\"}}","handlingStrategy":"validation","validationCode":"// Go: check before calling OIDC-dependent flows\ncfg := Conf.GetOIDC()\nif cfg == nil || !cfg.Enabled {\n\t// surface \"enable OIDC login first\" instead of calling login\n\treturn errors.New(\"OIDC login is disabled; enable it in Settings - Accounts\")\n}","typeGuard":"func oidcEnabled(cfg *conf.OIDC) bool { return cfg != nil && cfg.Enabled }","tryCatchPattern":"// JavaScript caller\ntry {\n  await fetchPost(\"/api/auth/loginOIDC\", {});\n} catch (e) {\n  if (e.msg === \"OIDC login is not enabled\") {\n    openSettings(\"Accounts\", \"OIDC\"); // prompt user to enable\n  } else { throw e; }\n}","preventionTips":["Enable OIDC in settings immediately after configuring provider fields","Re-check the enable flag after config restore or version upgrade","Gate OIDC login UI behind the enabled flag so users cannot trigger it","Keep a post-restart checklist verifying oidc.enabled persisted"],"tags":["oidc","configuration","authentication"],"backgroundTag":"feature-not-enabled","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}