siyuan-note/siyuan · critical
remote access requires at least one authentication method
Error message
remote access requires at least one authentication method
What it means
ValidateOIDCConfigurationChange prevents remote lockout: when the incoming request requires remote redirection and no authentication method remains available (OIDC disabled/absent, no alternative authentication, and no auth bypass), the change is rejected so a remote administrator cannot cut off their own access.
Solutions
- Enable an alternative authentication method (e.g. access auth password) before disabling OIDC
- Keep the OIDC configuration valid and Enabled when accessing remotely
- Perform the change from a local (loopback) session where requireRemoteRedirect is false
- Use bypassAuthentication only if you understand it grants unauthenticated access
Example fix
// before ValidateOIDCConfigurationChange(ctx, nil, true, false, false) // after ValidateOIDCConfigurationChange(ctx, nil, true, true, false) // alternative auth available
Defensive patterns
Strategy: validation
Validate before calling
// before disabling OIDC remotely, ensure a fallback exists:
if (remoteAccess && !oidcEnabled && !hasAlternativeAuth) throw new Error('would lock out remote access'); Try / catch
if err := ValidateOIDCConfigurationChange(ctx, cfg, requireRemote, hasAlt, bypass); err != nil {
log.Printf("config change rejected to prevent lockout: %v", err)
// retry from a local session or enable alternative auth first
} Prevention
- Always keep a working local session available when changing auth config
- Enable access-auth password before disabling OIDC on remote deployments
- Perform auth-configuration changes from loopback, not through a public URL
When it happens
Trigger: Calling ValidateOIDCConfigurationChange with (config == nil || !config.Enabled) == true, requireRemoteRedirect == true, hasAlternativeAuthentication == false, bypassAuthentication == false; also fired from InitConf and OIDCValidateStart under the same conditions.
Common situations: Admin accessing SiYuan over a public URL tries to disable OIDC (or the whole auth config fails validation) while no local session/password auth fallback exists; remote setup without any other login method.
Understand the failure class
Background: Conflicting config options: "cannot be used together" — configuration validation errors across open-source libraries — this error's family across 162 libraries.
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- OIDC validation configuration is missing
- A public HTTPS OIDC redirect URL is required for remote…
- OIDC client ID is required
- OIDC configuration changed during validation
- OIDC configuration is missing
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/9148b9d7c6c5b7fc.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/model/oidc.go:529
}
redirectURL := "http://127.0.0.1:6806/api/system/oidc/callback"
if config.RedirectURL != "" {
var err error
if redirectURL, err = validatePublicOIDCRedirectURL(config.RedirectURL); err != nil {
return err
}
}
validationContext, cancel := context.WithTimeout(ctx, oidcProviderTimeout)
defer cancel()
_, err := oidc_provider.New(validationContext, config, redirectURL)
return err
}
func ValidateOIDCConfigurationChange(ctx context.Context, config *conf.OIDC, requireRemoteRedirect,
hasAlternativeAuthentication, bypassAuthentication bool) error {
if config == nil || !config.Enabled {
if requireRemoteRedirect && !hasAlternativeAuthentication && !bypassAuthentication {
return errors.New("remote access requires at least one authentication method")
}
return nil
}
if requireRemoteRedirect {
if _, err := validatePublicOIDCRedirectURL(config.RedirectURL); err != nil {
return err
}
}
return ValidateOIDCProviderConfiguration(ctx, config)
}
func effectiveOIDCRedirectURL(c *gin.Context, flow string) (string, error) {
if flow == oidcFlowMobile {
return oidcMobileRedirectURL, nil
}
if flow == oidcFlowWeb && !IsLocalRequest(c) {
return validatePublicOIDCRedirectURL(Conf.GetOIDC().RedirectURL)
}View on GitHub (pinned to 9f775e8a12)