siyuan-note/siyuan · error
OIDC claim rules must include a claim and at least one value
Error message
OIDC claim rules must include a claim and at least one value
What it means
Each claim rule must name a claim key and list at least one accepted value; a nil rule, an empty Claim string, or an empty Values slice is meaningless as an access filter, so ValidateOIDCConfiguration rejects it.
Solutions
- Set a non-empty Claim name (e.g. 'email', 'groups') on every rule
- Provide at least one non-empty entry in each rule's Values array
- Remove empty/placeholder rules from the ClaimRules array before submitting
Example fix
// before
ClaimRules: []*conf.OIDCClaimRule{{Claim: "", Values: nil}}
// after
ClaimRules: []*conf.OIDCClaimRule{{Claim: "groups", Values: []string{"siyuan-users"}, Operator: conf.OIDCClaimOperatorContains}} Defensive patterns
Strategy: validation
Validate before calling
const valid = Array.isArray(rules) && rules.every(r => r && typeof r.claim === 'string' && r.claim.length > 0 && Array.isArray(r.values) && r.values.length > 0);
Type guard
const isFilledRule = (r) => !!r && typeof r.Claim === 'string' && r.Claim !== '' && Array.isArray(r.Values) && r.Values.length > 0;
Try / catch
if err := ValidateOIDCConfiguration(cfg); err != nil {
if strings.Contains(err.Error(), "claim and at least one value") { /* repair rule */ }
} Prevention
- Validate rule rows client-side before saving
- Strip empty placeholder rows from the form before submit
- Use typed constructors for rules that require claim and values
When it happens
Trigger: Iterating config.ClaimRules in ValidateOIDCConfiguration: any rule that is nil, has rule.Claim == "", or has len(rule.Values) == 0.
Common situations: Frontend submits a partially-filled rule row; JSON payload omits 'values' or 'claim' fields; programmatic config building appends an empty placeholder rule.
Understand the failure class
Background: "must not be empty", "cannot be empty" — required-field validation errors across open-source libraries — this error's family across 41 libraries.
Related errors
- createDocTree document contains unknown field
- each key must be an object
- invalid AI editor action data
- invalid bazaar index schema
- invalid capability arguments
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/91c98f78e142bfbe.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/model/oidc.go:484
return errors.New("OIDC issuer URL is required")
}
if (config.Provider == conf.OIDCProviderCustom || config.Provider == conf.OIDCProviderMicrosoft) && config.IssuerURL != "" {
issuer, err := url.Parse(config.IssuerURL)
if err != nil || issuer.Host == "" || issuer.User != nil || issuer.RawQuery != "" || issuer.Fragment != "" ||
(issuer.Scheme != "https" && !util.IsLocalHostname(issuer.Hostname())) {
return errors.New("OIDC issuer URL must use HTTPS unless it is a loopback address")
}
}
if config.Provider != conf.OIDCProviderCustom && config.Provider != conf.OIDCProviderGoogle &&
config.Provider != conf.OIDCProviderMicrosoft && config.Provider != conf.OIDCProviderGitHub {
return errors.New("Unsupported OIDC provider")
}
if !config.AllowAll && len(config.ClaimRules) == 0 {
return errors.New("OIDC login requires at least one claim rule when Allow all users is disabled")
}
for _, rule := range config.ClaimRules {
if rule == nil || rule.Claim == "" || len(rule.Values) == 0 {
return errors.New("OIDC claim rules must include a claim and at least one value")
}
if rule.Operator != conf.OIDCClaimOperatorEquals && rule.Operator != conf.OIDCClaimOperatorContains {
return errors.New("Unsupported OIDC claim rule operator")
}
for _, value := range rule.Values {
if value == "" {
return errors.New("OIDC claim rule values cannot be empty")
}
}
}
return nil
}
func ValidateOIDCMobileConfiguration(config *conf.OIDC) error {
if err := ValidateOIDCConfiguration(config); err != nil {
return err
}
if config.Provider == conf.OIDCProviderGoogle {View on GitHub (pinned to 9f775e8a12)