siyuan-note/siyuan · error

GitHub OAuth client secret is required

Error message

GitHub OAuth client secret is required

What it means

When the OIDC provider is GitHub, ValidateOIDCConfiguration additionally requires a non-empty ClientSecret. GitHub's OAuth flow needs the client secret for the token exchange, so an enabled GitHub provider with an empty secret is rejected with "GitHub OAuth client secret is required" before any network call is made.

Solutions

  1. Generate/copy the client secret from the GitHub OAuth App settings and paste it into the OIDC Client Secret field.
  2. If the secret was reset in GitHub, create a new one and update the SiYuan configuration.
  3. Re-save the settings and confirm the secret persisted in the workspace config before retrying login.
  4. If GitHub login is not actually wanted, switch the provider field to the intended provider so the GitHub-specific secret check no longer applies.

Example fix

// before
config := &conf.OIDC{Enabled: true, Provider: conf.OIDCProviderGitHub, ClientID: "Iv1.abc"}
// after
config := &conf.OIDC{Enabled: true, Provider: conf.OIDCProviderGitHub, ClientID: "Iv1.abc", ClientSecret: "ghp-secret-..."}
Defensive patterns

Strategy: validation

Validate before calling

// Go: pre-check for the GitHub provider
if cfg.Provider == conf.OIDCProviderGitHub && cfg.ClientSecret == "" {
	return errors.New("enter the GitHub OAuth app client secret before login")
}

Type guard

func hasGitHubSecret(cfg *conf.OIDC) bool {
	return cfg == nil || cfg.Provider != conf.OIDCProviderGitHub || cfg.ClientSecret != ""
}

Try / catch

// JavaScript caller
try {
  await startOIDCLogin();
} catch (e) {
  if (e.msg.includes("client secret is required")) {
    focusField("oidcClientSecret");
  } else { throw e; }
}

Prevention

When it happens

Trigger: Calling ValidateOIDCConfiguration (directly or via validateOIDCConfiguration/ValidateOIDCMobileConfiguration/ValidateOIDCProviderConfiguration) with config.Provider == conf.OIDCProviderGitHub and config.ClientSecret == "" — enabling GitHub login without entering the secret.

Common situations: Filling in only the client ID and assuming the secret is optional; losing the secret after a config restore; using a secret that was reset in the GitHub developer settings and cleared locally; swapping providers from Google to GitHub without adding a secret.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/2efac30966d581d1. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/oidc.go:463

	if !cancelOIDCValidation(input.PollToken, workspaceSession.OIDCBinding) {
		ret = apicontract.Failure[apicontract.Null](-1, oidcLanguage(369, "Invalid OIDC configuration"))
	}
	return
}

func validateOIDCConfiguration() error {
	return ValidateOIDCConfiguration(Conf.GetOIDC())
}

func ValidateOIDCConfiguration(config *conf.OIDC) error {
	if config == nil || !config.Enabled {
		return errors.New("OIDC login is not enabled")
	}
	if config.ClientID == "" {
		return errors.New("OIDC client ID is required")
	}
	if config.Provider == conf.OIDCProviderGitHub && config.ClientSecret == "" {
		return errors.New("GitHub OAuth client secret is required")
	}
	if (config.Provider == conf.OIDCProviderCustom || config.Provider == conf.OIDCProviderMicrosoft) && config.IssuerURL == "" {
		return errors.New("OIDC issuer URL is required")
	}
	if (config.Provider == conf.OIDCProviderCustom || config.Provider == conf.OIDCProviderMicrosoft) && config.IssuerURL != "" {
		issuer, err := url.Parse(config.IssuerURL)
		if err != nil || issuer.Host == "" || issuer.User != nil || issuer.RawQuery != "" || issuer.Fragment != "" ||
			(issuer.Scheme != "https" && !util.IsLocalHostname(issuer.Hostname())) {
			return errors.New("OIDC issuer URL must use HTTPS unless it is a loopback address")
		}
	}
	if config.Provider != conf.OIDCProviderCustom && config.Provider != conf.OIDCProviderGoogle &&
		config.Provider != conf.OIDCProviderMicrosoft && config.Provider != conf.OIDCProviderGitHub {
		return errors.New("Unsupported OIDC provider")
	}
	if !config.AllowAll && len(config.ClaimRules) == 0 {
		return errors.New("OIDC login requires at least one claim rule when Allow all users is disabled")
	}

View on GitHub (pinned to 9f775e8a12)