siyuan-note/siyuan · error

Google does not support the fixed SiYuan mobile OIDC…

Error message

Google does not support the fixed SiYuan mobile OIDC callback URI

What it means

The SiYuan mobile app uses a fixed OIDC redirect URI that cannot be registered per-tenant with Google, so ValidateOIDCMobileConfiguration rejects Google as the mobile OIDC provider. Google's redirect URI restrictions conflict with the hard-coded callback the app presents.

Solutions

  1. Choose a custom OIDC provider that allows arbitrary redirect URIs for mobile login
  2. Use Microsoft or GitHub, whose redirect handling is compatible with the fixed callback
  3. Restrict Google SSO to the desktop flow, where a loopback redirect is used

Example fix

// before
config.Provider = conf.OIDCProviderGoogle
return ValidateOIDCMobileConfiguration(config)
// after
config.Provider = conf.OIDCProviderCustom
return ValidateOIDCMobileConfiguration(config)
Defensive patterns

Strategy: validation

Validate before calling

const mobileUnsupported = ['google'];
if (mobile && mobileUnsupported.includes(config.provider)) { alert('Provider not supported for mobile OIDC'); }

Try / catch

if err := ValidateOIDCMobileConfiguration(cfg); err != nil {
    if strings.Contains(err.Error(), "Google does not support") { /* fall back to custom provider */ }
}

Prevention

When it happens

Trigger: Calling ValidateOIDCMobileConfiguration with config.Provider == conf.OIDCProviderGoogle after the general validation passes.

Common situations: Admin selects Google in the mobile OIDC provider settings; an API client reuses a Google desktop config for the mobile flow.

Understand the failure class

Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/c8c296664dadecb8. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/oidc.go:503

		}
		if rule.Operator != conf.OIDCClaimOperatorEquals && rule.Operator != conf.OIDCClaimOperatorContains {
			return errors.New("Unsupported OIDC claim rule operator")
		}
		for _, value := range rule.Values {
			if value == "" {
				return errors.New("OIDC claim rule values cannot be empty")
			}
		}
	}
	return nil
}

func ValidateOIDCMobileConfiguration(config *conf.OIDC) error {
	if err := ValidateOIDCConfiguration(config); err != nil {
		return err
	}
	if config.Provider == conf.OIDCProviderGoogle {
		return errors.New("Google does not support the fixed SiYuan mobile OIDC callback URI")
	}
	return nil
}

func ValidateOIDCProviderConfiguration(ctx context.Context, config *conf.OIDC) error {
	if err := ValidateOIDCConfiguration(config); err != nil {
		return err
	}
	redirectURL := "http://127.0.0.1:6806/api/system/oidc/callback"
	if config.RedirectURL != "" {
		var err error
		if redirectURL, err = validatePublicOIDCRedirectURL(config.RedirectURL); err != nil {
			return err
		}
	}
	validationContext, cancel := context.WithTimeout(ctx, oidcProviderTimeout)
	defer cancel()
	_, err := oidc_provider.New(validationContext, config, redirectURL)

View on GitHub (pinned to 9f775e8a12)