siyuan-note/siyuan · error

save OAuth client registration

Error message

save OAuth client registration: %w

What it means

After a successful dynamic client registration, the credential (client id/secret, endpoints, scopes) is persisted via putOAuthCredential. This error wraps any storage failure encountered while saving that registration, so the authorization flow cannot proceed to the browser redirect step. The %w wraps the underlying error from the credential store.

Solutions

  1. Check the wrapped error (%w) to identify the storage failure (disk full, permissions, corruption)
  2. Verify the SiYuan workspace data directory is writable and has free space
  3. Restart the kernel to clear any transient store locks, then retry authorization
  4. If the store is corrupted, restore the workspace from backup or repair the credential storage before retrying
Defensive patterns

Strategy: try-catch

Validate before calling

// Ensure the workspace data directory is writable before starting OAuth
if info, err := os.Stat(workspaceDir); err != nil || info.Mode().Perm()&0200 == 0 {
    return fmt.Errorf("workspace dir not writable")
}

Try / catch

if err := h.Authorize(ctx, true); err != nil {
    var perr *fs.PathError
    if errors.As(err, &perr) {
        // handle storage failure: fix disk/permissions then retry
    }
}

Prevention

When it happens

Trigger: Authorize() completes RegisterClient, the returned TokenAuthMethod is supported, but putOAuthCredential(registrationCredential) returns a non-nil error while persisting the new registration.

Common situations: Disk full or read-only data directory; workspace data corruption; concurrent writes to the credential store; permission problems on the SiYuan workspace folder.

Understand the failure class

Background: "failed to write file", "Could not save figure", "Error saving remote file" — file write failed: causes and fixes across languages and libraries — this error's family across 38 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/3512a79dc8c2fb28. Report an issue: GitHub.

Appendix: source

Thrown at kernel/mcp/client/oauth.go:335

			ClientSecret:        registration.ClientSecret,
			ClientSecretExpiry:  registration.ClientSecretExpiresAt,
			TokenEndpoint:       asm.TokenEndpoint,
			RevocationEndpoint:  asm.RevocationEndpoint,
			TokenAuthMethod:     registration.TokenEndpointAuthMethod,
			Scopes:              scopes,
		}
		if registrationCredential.TokenAuthMethod == "" {
			if registration.ClientSecret == "" {
				registrationCredential.TokenAuthMethod = "none"
			} else {
				registrationCredential.TokenAuthMethod = "client_secret_basic"
			}
		}
		if !isSupportedTokenAuthMethod(registrationCredential.TokenAuthMethod) {
			return fmt.Errorf("OAuth client registration returned an unsupported token endpoint authentication method")
		}
		if err = putOAuthCredential(registrationCredential); err != nil {
			return fmt.Errorf("save OAuth client registration: %w", err)
		}
	}

	authMethod := registrationCredential.TokenAuthMethod
	if authMethod == "" {
		if registrationCredential.ClientSecret == "" {
			authMethod = "none"
		} else {
			authMethod = "client_secret_basic"
		}
	}
	config := &oauth2.Config{
		ClientID:     registrationCredential.ClientID,
		ClientSecret: registrationCredential.ClientSecret,
		RedirectURL:  callbackURL,
		Scopes:       scopes,
		Endpoint: oauth2.Endpoint{
			AuthURL:   asm.AuthorizationEndpoint,

View on GitHub (pinned to 9f775e8a12)