siyuan-note/siyuan · error

OIDC configuration is missing

Error message

OIDC configuration is missing

What it means

oidc_provider.New is the constructor wrapping go-oidc/oauth2 for a configured identity provider. It validates its inputs upfront: a nil *conf.OIDC cannot yield a working provider, so it fails fast with this error. Called by OIDCValidateStart, ValidateOIDCProviderConfiguration, and getOIDCProvider.

Solutions

  1. Configure OIDC in Settings - About/Auth (save client ID, secret, issuer) before starting login/validation
  2. Check Conf.GetOIDC() returns a non-nil struct — restore/repair the workspace conf if the OIDC section is missing
  3. Guard callers: check config presence and show 'OIDC not configured' in the UI instead of invoking the flow
  4. In code, validate the config before calling New to get a clearer application-level error

Example fix

// before
provider, err := oidcprovider.New(ctx, conf.GetOIDC(), redirectURL) // nil conf
// after
conf := conf.GetOIDC()
if conf == nil { return errors.New("OIDC is not configured") }
provider, err := oidcprovider.New(ctx, conf, redirectURL)
Defensive patterns

Strategy: validation

Validate before calling

conf := model.GetOIDCConfig()
if conf == nil { show("OIDC login is not configured"); return }

Type guard

func oidcConfigured(c *conf.OIDC) bool { return c != nil }

Try / catch

provider, err := oidcprovider.New(ctx, cfg, redirectURL)
if err != nil && strings.Contains(err.Error(), "configuration is missing") {
    return nil, fmt.Errorf("OIDC login is not configured; set it in Settings first")
}

Prevention

When it happens

Trigger: getOIDCProvider invoked when Conf.GetOIDC() returns nil (OIDC never configured or feature disabled); OIDCValidateStart called with no candidate config; tests pass nil intentionally (TestOIDCProviderVerifiesNonceAndPKCE exercises the non-nil path).

Common situations: Admin hits the OIDC login endpoint before ever saving OIDC settings; config file corrupt/reset so the OIDC section is absent; code path calls New before loading conf in early-boot flows.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/6ddb45d103b427f9. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/oidc_provider/provider.go:37

	"github.com/coreos/go-oidc/v3/oidc"
	"github.com/siyuan-note/siyuan/kernel/conf"
	"golang.org/x/oauth2"
)

const (
	googleIssuer = "https://accounts.google.com"
)

type Provider struct {
	kind         string
	oauth2Config *oauth2.Config
	verifier     *oidc.IDTokenVerifier
}

func New(ctx context.Context, config *conf.OIDC, redirectURL string) (*Provider, error) {
	if config == nil {
		return nil, errors.New("OIDC configuration is missing")
	}
	if config.ClientID == "" {
		return nil, errors.New("OIDC client ID is required")
	}
	if redirectURL == "" {
		return nil, errors.New("OIDC redirect URL is required")
	}
	if config.Provider == conf.OIDCProviderGitHub && config.ClientSecret == "" {
		return nil, errors.New("GitHub OAuth client secret is required")
	}
	issuerURL := strings.TrimSpace(config.IssuerURL)
	switch config.Provider {
	case conf.OIDCProviderGoogle:
		issuerURL = googleIssuer
	case conf.OIDCProviderMicrosoft:
		// Microsoft 多租户端点的 issuer 会随租户变化,必须使用租户专属 issuer。
	case conf.OIDCProviderCustom:
	case conf.OIDCProviderGitHub:

View on GitHub (pinned to 9f775e8a12)