{"record":{"id":"e5247c403ad72812","repo":"siyuan-note/siyuan","slug":"invalid-cloud-login-token","errorCode":null,"errorMessage":"invalid cloud login token","messagePattern":"invalid cloud login token","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/apicontract/setting_cloud.go","lineNumber":51,"sourceCode":"\treturn json.Marshal(fields)\n}\n\nfunc (d *CloudLogin2faData) UnmarshalJSON(raw []byte) error {\n\tvar fields map[string]json.RawMessage\n\tif err := json.Unmarshal(raw, &fields); err != nil {\n\t\treturn err\n\t}\n\tcode, msg := fields[\"code\"], fields[\"msg\"]\n\tif len(code) == 0 || bytes.Equal(code, []byte(\"null\")) || json.Unmarshal(code, &d.Code) != nil {\n\t\treturn errors.New(\"invalid cloud login code\")\n\t}\n\tif len(msg) == 0 || bytes.Equal(msg, []byte(\"null\")) || json.Unmarshal(msg, &d.Msg) != nil {\n\t\treturn errors.New(\"invalid cloud login message\")\n\t}\n\tif d.Code == 0 {\n\t\tvar token string\n\t\tif json.Unmarshal(fields[\"token\"], &token) != nil || token == \"\" {\n\t\t\treturn errors.New(\"invalid cloud login token\")\n\t\t}\n\t}\n\td.Extra = make(map[string]JSONValue, len(fields)-2)\n\tfor key, raw := range fields {\n\t\tif key == \"code\" || key == \"msg\" {\n\t\t\tcontinue\n\t\t}\n\t\tvalue, err := EncodedJSONValue(raw)\n\t\tif err != nil {\n\t\t\treturn err\n\t\t}\n\t\td.Extra[key] = value\n\t}\n\treturn nil\n}\n\ntype Login2faEnvelope struct {\n\tCode int                `json:\"code\"`","sourceCodeStart":33,"sourceCodeEnd":69,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/apicontract/setting_cloud.go#L33-L69","documentation":"When the cloud login response code is 0 (success), UnmarshalJSON additionally requires a non-empty 'token' string field. Missing, null, non-string, or empty-string tokens produce 'invalid cloud login token'.","triggerScenarios":"A success (code=0) cloud login response that lacks 'token', has token:null or token:\"\", or a token that is not a JSON string.","commonSituations":"Cloud service authenticated the user but failed to issue/return a token, partial outage of the token service, or protocol drift where token moved to another field.","solutions":["Log the raw response and contact/verify cloud service token issuance","Retry the login request","Check the user's cloud account status (may be unable to receive tokens)","Update the client if the cloud API changed the token field name/location"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"function hasToken(v: unknown): v is { code: number; msg: string; token: string } {\n  return typeof v === 'object' && v !== null && typeof (v as any).token === 'string' && (v as any).token.length > 0;\n}","typeGuard":"function isNonEmptyString(v: unknown): v is string { return typeof v === 'string' && v.length > 0; }","tryCatchPattern":"try { const session = await cloudLogin(user, pass); } catch (e) { if (String(e).includes('invalid cloud login token')) { clearPartialSession(); notifyTokenServiceIssue(); } }","preventionTips":["Never persist a session without a valid token","Log raw responses when code=0 but no token is present","Monitor cloud token-service health","Handle re-login automatically when token issuance fails"],"tags":["cloud","auth","token","json"],"backgroundTag":"unexpected-api-response-shape","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}