siyuan-note/siyuan · error
A public HTTPS OIDC redirect URL is required for remote…
Error message
A public HTTPS OIDC redirect URL is required for remote access
What it means
validatePublicOIDCRedirectURL requires a non-empty redirect URL when validating remote access; an empty string gives it nothing to authenticate the callback against, so it errors rather than falling back to an insecure default.
Solutions
- Set conf.OIDC.RedirectURL to the full public callback, e.g. https://your-domain/api/system/oidc/callback
- Fill the redirect URL field in Settings - About/OIDC provider configuration before remote use
- If only local use is intended, access via loopback so public URL validation is skipped
Example fix
// before RedirectURL: "" // after RedirectURL: "https://siyuan.example.com/api/system/oidc/callback"
Defensive patterns
Strategy: validation
Validate before calling
if (!config.redirectURL || config.redirectURL.length === 0) { throw new Error('public redirect URL required for remote access'); } Try / catch
if err := ValidateOIDCConfigurationChange(ctx, cfg, true, false, false); err != nil {
if strings.Contains(err.Error(), "public HTTPS OIDC redirect URL is required") { /* prompt user to set RedirectURL */ }
} Prevention
- Fill the public redirect URL whenever the instance is reachable from the internet
- Keep the full callback path in your deployment notes/templates
- Verify after config resets that RedirectURL was restored
When it happens
Trigger: validatePublicOIDCRedirectURL("") invoked from ValidateOIDCConfigurationChange, ValidateOIDCProviderConfiguration, oidcValidationRedirectURL, or effectiveOIDCRedirectURL when conf.OIDC.RedirectURL is unset and remote redirection is required.
Common situations: Fresh OIDC config saved with the public redirect field left blank while accessing remotely; config reset losing RedirectURL; administrator switching from local to remote access without filling in the URL.
Understand the failure class
Background: "is required", "must be set", "missing required field": configuration validation errors across open-source libraries — this error's family across 36 libraries.
Related errors
- A loopback OIDC redirect URL is required for local access
- Desktop OIDC login requires a loopback listener
- OIDC client ID is required
- OIDC configuration changed during validation
- OIDC configuration is missing
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/27c73f8988f12c25.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/model/oidc.go:574
if !util.IsLocalHost(host) {
return "", errors.New("A loopback OIDC redirect URL is required for local access")
}
return scheme + "://" + host + "/api/system/oidc/callback", nil
}
func oidcValidationRedirectURL(c *gin.Context, config *conf.OIDC, mobile bool) (string, error) {
if mobile {
return oidcMobileRedirectURL, nil
}
if config.RedirectURL != "" {
return validatePublicOIDCRedirectURL(config.RedirectURL)
}
return effectiveOIDCRedirectURL(c, oidcFlowDesktop)
}
func validatePublicOIDCRedirectURL(redirectURL string) (string, error) {
if redirectURL == "" {
return "", errors.New("A public HTTPS OIDC redirect URL is required for remote access")
}
parsed, err := url.Parse(redirectURL)
if err != nil || parsed.Scheme == "" || parsed.Host == "" || parsed.Path != "/api/system/oidc/callback" ||
parsed.User != nil || parsed.RawQuery != "" || parsed.Fragment != "" {
return "", errors.New("OIDC redirect URL must end with /api/system/oidc/callback")
}
if parsed.Scheme != "https" {
return "", errors.New("Public OIDC redirect URL must use HTTPS")
}
return parsed.String(), nil
}
func getOIDCProvider(ctx context.Context, redirectURL string) (*oidc_provider.Provider, error) {
version := oidcConfigurationVersion(Conf.GetOIDC())
key := version + "\x00" + redirectURL
oidcProviders.Lock()
if oidcProviders.version != version {
oidcProviders.version = versionView on GitHub (pinned to 9f775e8a12)