siyuan-note/siyuan · error
OIDC claim rule values cannot be empty
Error message
OIDC claim rule values cannot be empty
What it means
Thrown by ValidateOIDCConfiguration when a claim rule in config.ClaimRules is nil, has an empty Claim name, or carries an empty Values list. Each rule must name a claim and at least one matching value to gate login; a rule object with missing claim name or no values is the faulting input (a sibling check enforces at least one rule when AllowAll is off).
Solutions
- Remove empty strings from the rule's Values array
- Trim whitespace and drop blank entries before building the rule
- In the UI, delete the emptied value row instead of saving it blank
Example fix
// before
Values: []string{"admin", ""}
// after
Values: []string{"admin"} Defensive patterns
Strategy: validation
Validate before calling
rules.forEach(r => { r.values = (r.values || []).map(v => (v || '').trim()).filter(v => v.length > 0); }); Type guard
const hasOnlyNonEmptyValues = (r) => r.Values.every(v => typeof v === 'string' && v.trim() !== '');
Try / catch
if err := ValidateOIDCConfiguration(cfg); err != nil {
if strings.Contains(err.Error(), "values cannot be empty") { /* sanitize Values */ }
} Prevention
- Trim and filter values when parsing user input (CSV, comma-separated fields)
- Remove value chips atomically in the UI
- Sanitize arrays before persisting config
When it happens
Trigger: A rule passes claim/operator checks but one of its Values entries is "" (e.g. Values: []string{"admin", ""}).
Common situations: Trailing empty value left in a comma-separated input field; user clears a value chip without removing the row; CSV import produces empty fields.
Understand the failure class
Background: "Must be a positive integer", "Invalid value", "Unsupported": the invalid-argument-value error family, when a library rejects the value you pass — this error's family across 35 libraries.
Related errors
- OIDC claim rules must include a claim and at least one value
- OIDC client ID is required
- OIDC issuer URL is required
- OIDC login requires at least one claim rule when Allow all…
- OIDC redirect URL is required
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/b3bf622a9f0a57d7.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/model/oidc.go:491
}
}
if config.Provider != conf.OIDCProviderCustom && config.Provider != conf.OIDCProviderGoogle &&
config.Provider != conf.OIDCProviderMicrosoft && config.Provider != conf.OIDCProviderGitHub {
return errors.New("Unsupported OIDC provider")
}
if !config.AllowAll && len(config.ClaimRules) == 0 {
return errors.New("OIDC login requires at least one claim rule when Allow all users is disabled")
}
for _, rule := range config.ClaimRules {
if rule == nil || rule.Claim == "" || len(rule.Values) == 0 {
return errors.New("OIDC claim rules must include a claim and at least one value")
}
if rule.Operator != conf.OIDCClaimOperatorEquals && rule.Operator != conf.OIDCClaimOperatorContains {
return errors.New("Unsupported OIDC claim rule operator")
}
for _, value := range rule.Values {
if value == "" {
return errors.New("OIDC claim rule values cannot be empty")
}
}
}
return nil
}
func ValidateOIDCMobileConfiguration(config *conf.OIDC) error {
if err := ValidateOIDCConfiguration(config); err != nil {
return err
}
if config.Provider == conf.OIDCProviderGoogle {
return errors.New("Google does not support the fixed SiYuan mobile OIDC callback URI")
}
return nil
}
func ValidateOIDCProviderConfiguration(ctx context.Context, config *conf.OIDC) error {
if err := ValidateOIDCConfiguration(config); err != nil {View on GitHub (pinned to 9f775e8a12)