siyuan-note/siyuan · critical

remote access requires at least one authentication method

Error message

remote access requires at least one authentication method

What it means

ValidateOIDCConfigurationChange prevents remote lockout: when the incoming request requires remote redirection and no authentication method remains available (OIDC disabled/absent, no alternative authentication, and no auth bypass), the change is rejected so a remote administrator cannot cut off their own access.

Solutions

  1. Enable an alternative authentication method (e.g. access auth password) before disabling OIDC
  2. Keep the OIDC configuration valid and Enabled when accessing remotely
  3. Perform the change from a local (loopback) session where requireRemoteRedirect is false
  4. Use bypassAuthentication only if you understand it grants unauthenticated access

Example fix

// before
ValidateOIDCConfigurationChange(ctx, nil, true, false, false)
// after
ValidateOIDCConfigurationChange(ctx, nil, true, true, false) // alternative auth available
Defensive patterns

Strategy: validation

Validate before calling

// before disabling OIDC remotely, ensure a fallback exists:
if (remoteAccess && !oidcEnabled && !hasAlternativeAuth) throw new Error('would lock out remote access');

Try / catch

if err := ValidateOIDCConfigurationChange(ctx, cfg, requireRemote, hasAlt, bypass); err != nil {
    log.Printf("config change rejected to prevent lockout: %v", err)
    // retry from a local session or enable alternative auth first
}

Prevention

When it happens

Trigger: Calling ValidateOIDCConfigurationChange with (config == nil || !config.Enabled) == true, requireRemoteRedirect == true, hasAlternativeAuthentication == false, bypassAuthentication == false; also fired from InitConf and OIDCValidateStart under the same conditions.

Common situations: Admin accessing SiYuan over a public URL tries to disable OIDC (or the whole auth config fails validation) while no local session/password auth fallback exists; remote setup without any other login method.

Understand the failure class

Background: Conflicting config options: "cannot be used together" — configuration validation errors across open-source libraries — this error's family across 162 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/9148b9d7c6c5b7fc. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/oidc.go:529

	}
	redirectURL := "http://127.0.0.1:6806/api/system/oidc/callback"
	if config.RedirectURL != "" {
		var err error
		if redirectURL, err = validatePublicOIDCRedirectURL(config.RedirectURL); err != nil {
			return err
		}
	}
	validationContext, cancel := context.WithTimeout(ctx, oidcProviderTimeout)
	defer cancel()
	_, err := oidc_provider.New(validationContext, config, redirectURL)
	return err
}

func ValidateOIDCConfigurationChange(ctx context.Context, config *conf.OIDC, requireRemoteRedirect,
	hasAlternativeAuthentication, bypassAuthentication bool) error {
	if config == nil || !config.Enabled {
		if requireRemoteRedirect && !hasAlternativeAuthentication && !bypassAuthentication {
			return errors.New("remote access requires at least one authentication method")
		}
		return nil
	}
	if requireRemoteRedirect {
		if _, err := validatePublicOIDCRedirectURL(config.RedirectURL); err != nil {
			return err
		}
	}
	return ValidateOIDCProviderConfiguration(ctx, config)
}

func effectiveOIDCRedirectURL(c *gin.Context, flow string) (string, error) {
	if flow == oidcFlowMobile {
		return oidcMobileRedirectURL, nil
	}
	if flow == oidcFlowWeb && !IsLocalRequest(c) {
		return validatePublicOIDCRedirectURL(Conf.GetOIDC().RedirectURL)
	}

View on GitHub (pinned to 9f775e8a12)