siyuan-note/siyuan · error

OIDC login is not enabled

Error message

OIDC login is not enabled

What it means

ValidateOIDCConfiguration checks the OIDC login configuration before any authentication flow runs. The first gate requires a non-nil config with Enabled=true. When OIDC is disabled (or the config object is missing entirely), any attempt to use or validate OIDC login returns "OIDC login is not enabled".

Solutions

  1. Enable OIDC in Settings - About (or set the enabled field of the OIDC config to true) and retry login.
  2. If the config is nil, configure the OIDC section completely before enabling it.
  3. Check workspace config/conf.json to confirm the oidc.enabled value persisted after restart.
  4. For programmatic use, enable the provider in the caller (e.g. the admin panel) before invoking OIDC login endpoints.

Example fix

// before
{"oidc": {"enabled": false, "clientID": "my-app"}}
// after
{"oidc": {"enabled": true, "clientID": "my-app"}}
Defensive patterns

Strategy: validation

Validate before calling

// Go: check before calling OIDC-dependent flows
cfg := Conf.GetOIDC()
if cfg == nil || !cfg.Enabled {
	// surface "enable OIDC login first" instead of calling login
	return errors.New("OIDC login is disabled; enable it in Settings - Accounts")
}

Type guard

func oidcEnabled(cfg *conf.OIDC) bool { return cfg != nil && cfg.Enabled }

Try / catch

// JavaScript caller
try {
  await fetchPost("/api/auth/loginOIDC", {});
} catch (e) {
  if (e.msg === "OIDC login is not enabled") {
    openSettings("Accounts", "OIDC"); // prompt user to enable
  } else { throw e; }
}

Prevention

When it happens

Trigger: Calling validateOIDCConfiguration (and thus any login flow depending on it) while Conf.GetOIDC() returns nil or a config with Enabled=false; invoking ValidateOIDCConfiguration/ValidateOIDCMobileConfiguration with an OIDC config whose enabled toggle is off; tests calling it with a default/unset config.

Common situations: Upgrading SiYuan and forgetting to re-enable OIDC after config reset; setting the provider fields but not flipping the enable switch; a fresh install where the OIDC section was never configured; mobile login pointing at a workspace with OIDC off.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/e411054d9b316980. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/oidc.go:457

	input := request
	if err := request.ParseError(); err != nil || input.PollToken == "" {
		ret = apicontract.Failure[apicontract.Null](-1, oidcLanguage(369, "Invalid OIDC configuration"))
		return
	}
	workspaceSession := util.GetWorkspaceSession(util.GetSession(c))
	if !cancelOIDCValidation(input.PollToken, workspaceSession.OIDCBinding) {
		ret = apicontract.Failure[apicontract.Null](-1, oidcLanguage(369, "Invalid OIDC configuration"))
	}
	return
}

func validateOIDCConfiguration() error {
	return ValidateOIDCConfiguration(Conf.GetOIDC())
}

func ValidateOIDCConfiguration(config *conf.OIDC) error {
	if config == nil || !config.Enabled {
		return errors.New("OIDC login is not enabled")
	}
	if config.ClientID == "" {
		return errors.New("OIDC client ID is required")
	}
	if config.Provider == conf.OIDCProviderGitHub && config.ClientSecret == "" {
		return errors.New("GitHub OAuth client secret is required")
	}
	if (config.Provider == conf.OIDCProviderCustom || config.Provider == conf.OIDCProviderMicrosoft) && config.IssuerURL == "" {
		return errors.New("OIDC issuer URL is required")
	}
	if (config.Provider == conf.OIDCProviderCustom || config.Provider == conf.OIDCProviderMicrosoft) && config.IssuerURL != "" {
		issuer, err := url.Parse(config.IssuerURL)
		if err != nil || issuer.Host == "" || issuer.User != nil || issuer.RawQuery != "" || issuer.Fragment != "" ||
			(issuer.Scheme != "https" && !util.IsLocalHostname(issuer.Hostname())) {
			return errors.New("OIDC issuer URL must use HTTPS unless it is a loopback address")
		}
	}
	if config.Provider != conf.OIDCProviderCustom && config.Provider != conf.OIDCProviderGoogle &&

View on GitHub (pinned to 9f775e8a12)