siyuan-note/siyuan · error
OIDC configuration is missing
Error message
OIDC configuration is missing
What it means
oidc_provider.New is the constructor wrapping go-oidc/oauth2 for a configured identity provider. It validates its inputs upfront: a nil *conf.OIDC cannot yield a working provider, so it fails fast with this error. Called by OIDCValidateStart, ValidateOIDCProviderConfiguration, and getOIDCProvider.
Solutions
- Configure OIDC in Settings - About/Auth (save client ID, secret, issuer) before starting login/validation
- Check Conf.GetOIDC() returns a non-nil struct — restore/repair the workspace conf if the OIDC section is missing
- Guard callers: check config presence and show 'OIDC not configured' in the UI instead of invoking the flow
- In code, validate the config before calling New to get a clearer application-level error
Example fix
// before
provider, err := oidcprovider.New(ctx, conf.GetOIDC(), redirectURL) // nil conf
// after
conf := conf.GetOIDC()
if conf == nil { return errors.New("OIDC is not configured") }
provider, err := oidcprovider.New(ctx, conf, redirectURL) Defensive patterns
Strategy: validation
Validate before calling
conf := model.GetOIDCConfig()
if conf == nil { show("OIDC login is not configured"); return } Type guard
func oidcConfigured(c *conf.OIDC) bool { return c != nil } Try / catch
provider, err := oidcprovider.New(ctx, cfg, redirectURL)
if err != nil && strings.Contains(err.Error(), "configuration is missing") {
return nil, fmt.Errorf("OIDC login is not configured; set it in Settings first")
} Prevention
- Check Conf.GetOIDC() for nil before any OIDC flow
- Show 'not configured' state in the login UI when the OIDC section is absent
- Run ValidateOIDCProviderConfiguration as a preflight in the settings panel
When it happens
Trigger: getOIDCProvider invoked when Conf.GetOIDC() returns nil (OIDC never configured or feature disabled); OIDCValidateStart called with no candidate config; tests pass nil intentionally (TestOIDCProviderVerifiesNonceAndPKCE exercises the non-nil path).
Common situations: Admin hits the OIDC login endpoint before ever saving OIDC settings; config file corrupt/reset so the OIDC section is absent; code path calls New before loading conf in early-boot flows.
Related errors
- A public HTTPS OIDC redirect URL is required for remote…
- OIDC client ID is required
- OIDC configuration changed during validation
- OIDC login requires at least one claim rule when Allow all…
- OIDC validation configuration is missing
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/6ddb45d103b427f9.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/model/oidc_provider/provider.go:37
"github.com/coreos/go-oidc/v3/oidc"
"github.com/siyuan-note/siyuan/kernel/conf"
"golang.org/x/oauth2"
)
const (
googleIssuer = "https://accounts.google.com"
)
type Provider struct {
kind string
oauth2Config *oauth2.Config
verifier *oidc.IDTokenVerifier
}
func New(ctx context.Context, config *conf.OIDC, redirectURL string) (*Provider, error) {
if config == nil {
return nil, errors.New("OIDC configuration is missing")
}
if config.ClientID == "" {
return nil, errors.New("OIDC client ID is required")
}
if redirectURL == "" {
return nil, errors.New("OIDC redirect URL is required")
}
if config.Provider == conf.OIDCProviderGitHub && config.ClientSecret == "" {
return nil, errors.New("GitHub OAuth client secret is required")
}
issuerURL := strings.TrimSpace(config.IssuerURL)
switch config.Provider {
case conf.OIDCProviderGoogle:
issuerURL = googleIssuer
case conf.OIDCProviderMicrosoft:
// Microsoft 多租户端点的 issuer 会随租户变化,必须使用租户专属 issuer。
case conf.OIDCProviderCustom:
case conf.OIDCProviderGitHub:View on GitHub (pinned to 9f775e8a12)