siyuan-note/siyuan · error

unsupported OIDC provider

Error message

unsupported OIDC provider [%s]

What it means

New switches on config.Provider to select a known issuer or GitHub-specific implementation; the default branch rejects any provider value outside the supported set (Google, Microsoft, Custom, GitHub). This guards against invalid enum values in the configuration that would otherwise lead to an undefined flow. The provider name is interpolated into the message for diagnosis.

Solutions

  1. Set config.Provider to a supported value: the constants for Google, Microsoft, GitHub, or Custom (for a generic issuer URL).
  2. For a non-listed IdP that speaks standard OIDC discovery, use the Custom provider and set IssuerURL instead of inventing a provider name.
  3. Inspect the persisted configuration file and correct/normalize the provider field after upgrading.
  4. Add validation in the settings UI to restrict the field to the supported enum.

Example fix

// before
cfg := &conf.OIDC{Provider: "auth0", IssuerURL: "https://xxx.auth0.com"}
provider, err := New(cfg, redirectURL)
// after
cfg := &conf.OIDC{Provider: conf.OIDCProviderCustom, IssuerURL: "https://xxx.auth0.com"}
provider, err := New(cfg, redirectURL)
Defensive patterns

Strategy: validation

Validate before calling

supported := map[string]bool{conf.OIDCProviderGoogle: true, conf.OIDCProviderMicrosoft: true, conf.OIDCProviderCustom: true, conf.OIDCProviderGitHub: true}
if !supported[cfg.Provider] {
    return fmt.Errorf("provider %q is not supported; use google, microsoft, github or custom", cfg.Provider)
}

Try / catch

if err != nil {
    if strings.Contains(err.Error(), "unsupported OIDC provider") {
        // extract the provider name between [ ] and show valid options
    }
    return err
}

Prevention

When it happens

Trigger: Calling New with config.Provider set to a string that is not one of conf.OIDCProviderGoogle / OIDCProviderMicrosoft / OIDCProviderCustom / OIDCProviderGitHub — typically from a hand-edited or partially migrated conf JSON.

Common situations: Upgrades where the enum constant was renamed and old persisted configs still hold the old value; admins typing provider names like "Auth0" or "keycloak" into a free-text field expecting support; config files copied from other software with different provider identifiers.

Understand the failure class

Background: Invalid enum value errors: "Unknown type", "Invalid scope", "must be one of" — when a string is not on the library's allowed list — this error's family across 23 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/689f078518e37518. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/oidc_provider/provider.go:58

		return nil, errors.New("OIDC client ID is required")
	}
	if redirectURL == "" {
		return nil, errors.New("OIDC redirect URL is required")
	}
	if config.Provider == conf.OIDCProviderGitHub && config.ClientSecret == "" {
		return nil, errors.New("GitHub OAuth client secret is required")
	}
	issuerURL := strings.TrimSpace(config.IssuerURL)
	switch config.Provider {
	case conf.OIDCProviderGoogle:
		issuerURL = googleIssuer
	case conf.OIDCProviderMicrosoft:
		// Microsoft 多租户端点的 issuer 会随租户变化,必须使用租户专属 issuer。
	case conf.OIDCProviderCustom:
	case conf.OIDCProviderGitHub:
		return newGitHub(config, redirectURL), nil
	default:
		return nil, fmt.Errorf("unsupported OIDC provider [%s]", config.Provider)
	}
	if issuerURL == "" {
		return nil, errors.New("OIDC issuer URL is required")
	}
	discovered, err := oidc.NewProvider(ctx, issuerURL)
	if err != nil {
		return nil, fmt.Errorf("discover OIDC provider failed: %w", err)
	}
	scopes := append([]string{}, config.Scopes...)
	if !contains(scopes, oidc.ScopeOpenID) {
		scopes = append([]string{oidc.ScopeOpenID}, scopes...)
	}
	return &Provider{
		kind: conf.OIDCProviderCustom,
		oauth2Config: &oauth2.Config{
			ClientID:     config.ClientID,
			ClientSecret: config.ClientSecret,
			Endpoint:     discovered.Endpoint(),

View on GitHub (pinned to 9f775e8a12)