siyuan-note/siyuan · error

OIDC claim rule values cannot be empty

Error message

OIDC claim rule values cannot be empty

What it means

Thrown by ValidateOIDCConfiguration when a claim rule in config.ClaimRules is nil, has an empty Claim name, or carries an empty Values list. Each rule must name a claim and at least one matching value to gate login; a rule object with missing claim name or no values is the faulting input (a sibling check enforces at least one rule when AllowAll is off).

Solutions

  1. Remove empty strings from the rule's Values array
  2. Trim whitespace and drop blank entries before building the rule
  3. In the UI, delete the emptied value row instead of saving it blank

Example fix

// before
Values: []string{"admin", ""}
// after
Values: []string{"admin"}
Defensive patterns

Strategy: validation

Validate before calling

rules.forEach(r => { r.values = (r.values || []).map(v => (v || '').trim()).filter(v => v.length > 0); });

Type guard

const hasOnlyNonEmptyValues = (r) => r.Values.every(v => typeof v === 'string' && v.trim() !== '');

Try / catch

if err := ValidateOIDCConfiguration(cfg); err != nil {
    if strings.Contains(err.Error(), "values cannot be empty") { /* sanitize Values */ }
}

Prevention

When it happens

Trigger: A rule passes claim/operator checks but one of its Values entries is "" (e.g. Values: []string{"admin", ""}).

Common situations: Trailing empty value left in a comma-separated input field; user clears a value chip without removing the row; CSV import produces empty fields.

Understand the failure class

Background: "Must be a positive integer", "Invalid value", "Unsupported": the invalid-argument-value error family, when a library rejects the value you pass — this error's family across 35 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/b3bf622a9f0a57d7. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/oidc.go:491

		}
	}
	if config.Provider != conf.OIDCProviderCustom && config.Provider != conf.OIDCProviderGoogle &&
		config.Provider != conf.OIDCProviderMicrosoft && config.Provider != conf.OIDCProviderGitHub {
		return errors.New("Unsupported OIDC provider")
	}
	if !config.AllowAll && len(config.ClaimRules) == 0 {
		return errors.New("OIDC login requires at least one claim rule when Allow all users is disabled")
	}
	for _, rule := range config.ClaimRules {
		if rule == nil || rule.Claim == "" || len(rule.Values) == 0 {
			return errors.New("OIDC claim rules must include a claim and at least one value")
		}
		if rule.Operator != conf.OIDCClaimOperatorEquals && rule.Operator != conf.OIDCClaimOperatorContains {
			return errors.New("Unsupported OIDC claim rule operator")
		}
		for _, value := range rule.Values {
			if value == "" {
				return errors.New("OIDC claim rule values cannot be empty")
			}
		}
	}
	return nil
}

func ValidateOIDCMobileConfiguration(config *conf.OIDC) error {
	if err := ValidateOIDCConfiguration(config); err != nil {
		return err
	}
	if config.Provider == conf.OIDCProviderGoogle {
		return errors.New("Google does not support the fixed SiYuan mobile OIDC callback URI")
	}
	return nil
}

func ValidateOIDCProviderConfiguration(ctx context.Context, config *conf.OIDC) error {
	if err := ValidateOIDCConfiguration(config); err != nil {

View on GitHub (pinned to 9f775e8a12)