【问题标题】:IdentityServer4 and Web API in same projectIdentityServer4 和 Web API 在同一个项目中
【发布时间】:2018-12-06 15:51:33
【问题描述】:

我有一个 IdentityServer 和一个 MVC-Client,IdentityServer 有自己的 Web API 来为其客户端提供用户管理。 MVC 客户端使用HybridAndClientCredentials 授权类型与 IdentityServer 交互。我对验证客户的用户没有任何问题。问题是当我尝试使用经过身份验证的用户从 IdentityServer 调用某些 API 时,服务器返回登录视图而不是 API 的结果。

这是我的客户端配置:

new Client
{
    ClientId = "mvc.identity.management",
    ClientName = "Identity Management",
    AllowedGrantTypes = GrantTypes.Hybrid,

    RequireConsent = false,

    ClientSecrets =
    {
        new Secret("somesecret".Sha256())
    },

    RedirectUris = { "http://localhost:5001/signin-oidc" },
    PostLogoutRedirectUris = { "http://localhost:5001/signout-callback-oidc" },

    AllowedScopes =
    {
        IdentityServerConstants.StandardScopes.OpenId,
        IdentityServerConstants.StandardScopes.Profile
    }
}

和客户

    JwtSecurityTokenHandler.DefaultInboundClaimTypeMap.Clear();

    services.AddAuthentication(options =>
    {
        options.DefaultScheme = "Cookies";
        options.DefaultChallengeScheme = "oidc";
    })
    .AddCookie("Cookies")
    .AddOpenIdConnect("oidc", options =>
    {
        options.SignInScheme = "Cookies";

        options.Authority = "http://localhost:5000";
        options.RequireHttpsMetadata = false;

        options.ClientSecret = "somesecret";
        options.ResponseType = "code id_token";
        options.GetClaimsFromUserInfoEndpoint = true;

        options.ClientId = "mvc.identity.management";
        options.SaveTokens = true;
    });

任何建议都会有所帮助。

【问题讨论】:

  • 为什么要从身份服务器调用 API?您的用户已通过身份验证,用户应该调用 API,或者 IdentityServer,应该有自己的凭据来调用 api。
  • 我在客户端调用 API
  • 您的 api 代码在哪里,您的 api 需要针对身份服务器验证该令牌
  • 没错,这就是问题所在,我能够从服务器获取 access_token 并设置 HttpClient 承载,但是当我尝试调用 API 而不是结果时,服务器将登录视图作为字符串返回给客户端。
  • 发布您的 API 启动代码,Api 需要针对 Identity Server 验证令牌。

标签: asp.net-mvc asp.net-core asp.net-web-api2 identityserver4


【解决方案1】:

也许为时已晚,但其他人可能会提出这个问题。 解决方案是使用LocalApi,这是IdentityServer4 的内置功能。 您创建一个LocalApi 并使用自定义范围授权它,您的客户应添加该范围IdentityServerApi。 完整的资源可在此处获得: https://docs.identityserver.io/en/latest/topics/add_apis.html

【讨论】:

    猜你喜欢
    • 2017-01-28
    • 2016-07-06
    • 2018-08-21
    • 2019-05-11
    • 2019-09-18
    • 1970-01-01
    • 2019-10-30
    • 2015-06-05
    • 2015-09-06
    相关资源
    最近更新 更多