siyuan-note/siyuan · error

A public HTTPS OIDC redirect URL is required for remote…

Error message

A public HTTPS OIDC redirect URL is required for remote access

What it means

validatePublicOIDCRedirectURL requires a non-empty redirect URL when validating remote access; an empty string gives it nothing to authenticate the callback against, so it errors rather than falling back to an insecure default.

Solutions

  1. Set conf.OIDC.RedirectURL to the full public callback, e.g. https://your-domain/api/system/oidc/callback
  2. Fill the redirect URL field in Settings - About/OIDC provider configuration before remote use
  3. If only local use is intended, access via loopback so public URL validation is skipped

Example fix

// before
RedirectURL: ""
// after
RedirectURL: "https://siyuan.example.com/api/system/oidc/callback"
Defensive patterns

Strategy: validation

Validate before calling

if (!config.redirectURL || config.redirectURL.length === 0) { throw new Error('public redirect URL required for remote access'); }

Try / catch

if err := ValidateOIDCConfigurationChange(ctx, cfg, true, false, false); err != nil {
    if strings.Contains(err.Error(), "public HTTPS OIDC redirect URL is required") { /* prompt user to set RedirectURL */ }
}

Prevention

When it happens

Trigger: validatePublicOIDCRedirectURL("") invoked from ValidateOIDCConfigurationChange, ValidateOIDCProviderConfiguration, oidcValidationRedirectURL, or effectiveOIDCRedirectURL when conf.OIDC.RedirectURL is unset and remote redirection is required.

Common situations: Fresh OIDC config saved with the public redirect field left blank while accessing remotely; config reset losing RedirectURL; administrator switching from local to remote access without filling in the URL.

Understand the failure class

Background: "is required", "must be set", "missing required field": configuration validation errors across open-source libraries — this error's family across 36 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/27c73f8988f12c25. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/oidc.go:574

	if !util.IsLocalHost(host) {
		return "", errors.New("A loopback OIDC redirect URL is required for local access")
	}
	return scheme + "://" + host + "/api/system/oidc/callback", nil
}

func oidcValidationRedirectURL(c *gin.Context, config *conf.OIDC, mobile bool) (string, error) {
	if mobile {
		return oidcMobileRedirectURL, nil
	}
	if config.RedirectURL != "" {
		return validatePublicOIDCRedirectURL(config.RedirectURL)
	}
	return effectiveOIDCRedirectURL(c, oidcFlowDesktop)
}

func validatePublicOIDCRedirectURL(redirectURL string) (string, error) {
	if redirectURL == "" {
		return "", errors.New("A public HTTPS OIDC redirect URL is required for remote access")
	}
	parsed, err := url.Parse(redirectURL)
	if err != nil || parsed.Scheme == "" || parsed.Host == "" || parsed.Path != "/api/system/oidc/callback" ||
		parsed.User != nil || parsed.RawQuery != "" || parsed.Fragment != "" {
		return "", errors.New("OIDC redirect URL must end with /api/system/oidc/callback")
	}
	if parsed.Scheme != "https" {
		return "", errors.New("Public OIDC redirect URL must use HTTPS")
	}
	return parsed.String(), nil
}

func getOIDCProvider(ctx context.Context, redirectURL string) (*oidc_provider.Provider, error) {
	version := oidcConfigurationVersion(Conf.GetOIDC())
	key := version + "\x00" + redirectURL
	oidcProviders.Lock()
	if oidcProviders.version != version {
		oidcProviders.version = version

View on GitHub (pinned to 9f775e8a12)