siyuan-note/siyuan · error
OIDC client ID is required
Error message
OIDC client ID is required
What it means
oidc_provider.New requires a non-empty ClientID because the OAuth2 client cannot build authorize/token requests without it. This is an upfront constructor validation alongside the redirect URL and GitHub client-secret checks.
Solutions
- Fill in the Client ID in the OIDC settings panel (from the IdP/console) and save, then retry
- Inspect the workspace conf to confirm the OIDC ClientID key is spelled correctly and non-empty
- Call ValidateOIDCProviderConfiguration before starting login to get precise field-level errors in the UI
- If using GitHub provider mode, also ensure ClientSecret is set (next check in the constructor)
Example fix
// before
Conf.OIDC = {ClientID: "", ClientSecret: "abc", Provider: "generic"}
// after
Conf.OIDC = {ClientID: "my-client-id", ClientSecret: "abc", Provider: "generic"} Defensive patterns
Strategy: validation
Validate before calling
if cfg == nil || strings.TrimSpace(cfg.ClientID) == "" { return errors.New("OIDC client ID must be set in settings") } Type guard
func hasClientID(c *conf.OIDC) bool { return c != nil && c.ClientID != "" } Try / catch
provider, err := oidcprovider.New(ctx, cfg, redirectURL)
if err != nil && strings.Contains(err.Error(), "client ID is required") {
return nil, fmt.Errorf("open Settings - Auth and enter the client ID from your identity provider")
} Prevention
- Preflight-validate the settings form (client ID required) before saving
- Watch for hand-edited configs with misspelled JSON keys silently emptying ClientID
- When copying config between workspaces, verify client ID/secret survive the move
When it happens
Trigger: OIDCValidateStart, ValidateOIDCProviderConfiguration, or getOIDCProvider passes a conf.OIDC whose ClientID is empty — settings saved incompletely (client secret set but client ID blank), config edited by hand, or a config reset cleared the field.
Common situations: Admin saved the OIDC panel after clearing the client ID field; migrating config between workspaces lost the client ID; GitHub provider mode with secret but no ID; config file hand-edited with wrong JSON keys so ClientID unmarshals to empty.
Understand the failure class
Background: "is required", "must be set", "missing required field": configuration validation errors across open-source libraries — this error's family across 36 libraries.
Related errors
- OIDC login requires at least one claim rule when Allow all…
- A public HTTPS OIDC redirect URL is required for remote…
- Argon2id Iterations too high (maximum 10)
- Argon2id Memory too high (maximum 256 MB)
- Argon2id Parallelism must be between 1 and 16
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/d2d0f29b94909fa4.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/model/oidc_provider/provider.go:40
"golang.org/x/oauth2"
)
const (
googleIssuer = "https://accounts.google.com"
)
type Provider struct {
kind string
oauth2Config *oauth2.Config
verifier *oidc.IDTokenVerifier
}
func New(ctx context.Context, config *conf.OIDC, redirectURL string) (*Provider, error) {
if config == nil {
return nil, errors.New("OIDC configuration is missing")
}
if config.ClientID == "" {
return nil, errors.New("OIDC client ID is required")
}
if redirectURL == "" {
return nil, errors.New("OIDC redirect URL is required")
}
if config.Provider == conf.OIDCProviderGitHub && config.ClientSecret == "" {
return nil, errors.New("GitHub OAuth client secret is required")
}
issuerURL := strings.TrimSpace(config.IssuerURL)
switch config.Provider {
case conf.OIDCProviderGoogle:
issuerURL = googleIssuer
case conf.OIDCProviderMicrosoft:
// Microsoft 多租户端点的 issuer 会随租户变化,必须使用租户专属 issuer。
case conf.OIDCProviderCustom:
case conf.OIDCProviderGitHub:
return newGitHub(config, redirectURL), nil
default:
return nil, fmt.Errorf("unsupported OIDC provider [%s]", config.Provider)View on GitHub (pinned to 9f775e8a12)