siyuan-note/siyuan · error

Unsupported OIDC provider

Error message

Unsupported OIDC provider

What it means

ValidateOIDCConfiguration only accepts the four known providers: custom, Google, Microsoft, and GitHub. If config.Provider holds any other value (unknown string, empty, or an invalid enum), validation stops with "Unsupported OIDC provider". This guards against typos and misconfigured deployments before the OAuth flow starts.

Solutions

  1. Set the provider to one of the supported values (custom, google, microsoft, github) in Settings - Accounts - OIDC.
  2. If hand-editing the config, use the exact provider identifiers accepted by conf.OIDC constants.
  3. Re-select the provider in the UI and save so the value is validated before use.
  4. Check for schema drift if the config came from an old version and re-apply settings.

Example fix

// before
{"oidc": {"enabled": true, "provider": "okta"}}
// after
{"oidc": {"enabled": true, "provider": "custom", "issuerURL": "https://your-org.okta.com"}}
Defensive patterns

Strategy: validation

Validate before calling

// Go: restrict provider values before saving/validating
switch cfg.Provider {
case conf.OIDCProviderCustom, conf.OIDCProviderGoogle,
	conf.OIDCProviderMicrosoft, conf.OIDCProviderGitHub:
	// ok
default:
	return errors.New("provider must be custom, google, microsoft, or github")
}

Type guard

func knownProvider(p string) bool {
	switch p {
	case conf.OIDCProviderCustom, conf.OIDCProviderGoogle,
		conf.OIDCProviderMicrosoft, conf.OIDCProviderGitHub:
		return true
	}
	return false
}

Try / catch

// JavaScript caller
try {
  await saveOIDCSettings(cfg);
} catch (e) {
  if (e.msg.includes("Unsupported OIDC provider")) {
    resetProviderSelection(); // force choosing from the supported list
  } else { throw e; }
}

Prevention

When it happens

Trigger: Calling ValidateOIDCConfiguration with config.Provider not equal to OIDCProviderCustom, OIDCProviderGoogle, OIDCProviderMicrosoft, or OIDCProviderGitHub — e.g. an empty provider field, a hand-edited config value, or a config file from an older/newer schema.

Common situations: Hand-editing workspace conf.json and mistyping the provider name; restoring a config where the provider field was blank; a script writing an arbitrary provider string; switching providers and clearing the field instead of selecting one.

Understand the failure class

Background: Invalid enum value errors: "Unknown type", "Invalid scope", "must be one of" — when a string is not on the library's allowed list — this error's family across 23 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/98fe778fff5b84ca. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/oidc.go:477

	if config.ClientID == "" {
		return errors.New("OIDC client ID is required")
	}
	if config.Provider == conf.OIDCProviderGitHub && config.ClientSecret == "" {
		return errors.New("GitHub OAuth client secret is required")
	}
	if (config.Provider == conf.OIDCProviderCustom || config.Provider == conf.OIDCProviderMicrosoft) && config.IssuerURL == "" {
		return errors.New("OIDC issuer URL is required")
	}
	if (config.Provider == conf.OIDCProviderCustom || config.Provider == conf.OIDCProviderMicrosoft) && config.IssuerURL != "" {
		issuer, err := url.Parse(config.IssuerURL)
		if err != nil || issuer.Host == "" || issuer.User != nil || issuer.RawQuery != "" || issuer.Fragment != "" ||
			(issuer.Scheme != "https" && !util.IsLocalHostname(issuer.Hostname())) {
			return errors.New("OIDC issuer URL must use HTTPS unless it is a loopback address")
		}
	}
	if config.Provider != conf.OIDCProviderCustom && config.Provider != conf.OIDCProviderGoogle &&
		config.Provider != conf.OIDCProviderMicrosoft && config.Provider != conf.OIDCProviderGitHub {
		return errors.New("Unsupported OIDC provider")
	}
	if !config.AllowAll && len(config.ClaimRules) == 0 {
		return errors.New("OIDC login requires at least one claim rule when Allow all users is disabled")
	}
	for _, rule := range config.ClaimRules {
		if rule == nil || rule.Claim == "" || len(rule.Values) == 0 {
			return errors.New("OIDC claim rules must include a claim and at least one value")
		}
		if rule.Operator != conf.OIDCClaimOperatorEquals && rule.Operator != conf.OIDCClaimOperatorContains {
			return errors.New("Unsupported OIDC claim rule operator")
		}
		for _, value := range rule.Values {
			if value == "" {
				return errors.New("OIDC claim rule values cannot be empty")
			}
		}
	}
	return nil

View on GitHub (pinned to 9f775e8a12)