siyuan-note/siyuan · error
Google does not support the fixed SiYuan mobile OIDC…
Error message
Google does not support the fixed SiYuan mobile OIDC callback URI
What it means
The SiYuan mobile app uses a fixed OIDC redirect URI that cannot be registered per-tenant with Google, so ValidateOIDCMobileConfiguration rejects Google as the mobile OIDC provider. Google's redirect URI restrictions conflict with the hard-coded callback the app presents.
Solutions
- Choose a custom OIDC provider that allows arbitrary redirect URIs for mobile login
- Use Microsoft or GitHub, whose redirect handling is compatible with the fixed callback
- Restrict Google SSO to the desktop flow, where a loopback redirect is used
Example fix
// before config.Provider = conf.OIDCProviderGoogle return ValidateOIDCMobileConfiguration(config) // after config.Provider = conf.OIDCProviderCustom return ValidateOIDCMobileConfiguration(config)
Defensive patterns
Strategy: validation
Validate before calling
const mobileUnsupported = ['google'];
if (mobile && mobileUnsupported.includes(config.provider)) { alert('Provider not supported for mobile OIDC'); } Try / catch
if err := ValidateOIDCMobileConfiguration(cfg); err != nil {
if strings.Contains(err.Error(), "Google does not support") { /* fall back to custom provider */ }
} Prevention
- Filter the mobile provider picker to supported providers only
- Reuse desktop Google configs only for the desktop flow
- Document the fixed mobile callback URI limitation
When it happens
Trigger: Calling ValidateOIDCMobileConfiguration with config.Provider == conf.OIDCProviderGoogle after the general validation passes.
Common situations: Admin selects Google in the mobile OIDC provider settings; an API client reuses a Google desktop config for the mobile flow.
Understand the failure class
Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.
Related errors
- A loopback OIDC redirect URL is required for local access
- A public HTTPS OIDC redirect URL is required for remote…
- decode OIDC claims failed
- Desktop OIDC login requires a loopback listener
- discover OIDC provider failed
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/c8c296664dadecb8.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/model/oidc.go:503
}
if rule.Operator != conf.OIDCClaimOperatorEquals && rule.Operator != conf.OIDCClaimOperatorContains {
return errors.New("Unsupported OIDC claim rule operator")
}
for _, value := range rule.Values {
if value == "" {
return errors.New("OIDC claim rule values cannot be empty")
}
}
}
return nil
}
func ValidateOIDCMobileConfiguration(config *conf.OIDC) error {
if err := ValidateOIDCConfiguration(config); err != nil {
return err
}
if config.Provider == conf.OIDCProviderGoogle {
return errors.New("Google does not support the fixed SiYuan mobile OIDC callback URI")
}
return nil
}
func ValidateOIDCProviderConfiguration(ctx context.Context, config *conf.OIDC) error {
if err := ValidateOIDCConfiguration(config); err != nil {
return err
}
redirectURL := "http://127.0.0.1:6806/api/system/oidc/callback"
if config.RedirectURL != "" {
var err error
if redirectURL, err = validatePublicOIDCRedirectURL(config.RedirectURL); err != nil {
return err
}
}
validationContext, cancel := context.WithTimeout(ctx, oidcProviderTimeout)
defer cancel()
_, err := oidc_provider.New(validationContext, config, redirectURL)View on GitHub (pinned to 9f775e8a12)