【发布时间】:2018-12-06 15:51:33
【问题描述】:
我有一个 IdentityServer 和一个 MVC-Client,IdentityServer 有自己的 Web API 来为其客户端提供用户管理。
MVC 客户端使用HybridAndClientCredentials 授权类型与 IdentityServer 交互。我对验证客户的用户没有任何问题。问题是当我尝试使用经过身份验证的用户从 IdentityServer 调用某些 API 时,服务器返回登录视图而不是 API 的结果。
这是我的客户端配置:
new Client
{
ClientId = "mvc.identity.management",
ClientName = "Identity Management",
AllowedGrantTypes = GrantTypes.Hybrid,
RequireConsent = false,
ClientSecrets =
{
new Secret("somesecret".Sha256())
},
RedirectUris = { "http://localhost:5001/signin-oidc" },
PostLogoutRedirectUris = { "http://localhost:5001/signout-callback-oidc" },
AllowedScopes =
{
IdentityServerConstants.StandardScopes.OpenId,
IdentityServerConstants.StandardScopes.Profile
}
}
和客户
JwtSecurityTokenHandler.DefaultInboundClaimTypeMap.Clear();
services.AddAuthentication(options =>
{
options.DefaultScheme = "Cookies";
options.DefaultChallengeScheme = "oidc";
})
.AddCookie("Cookies")
.AddOpenIdConnect("oidc", options =>
{
options.SignInScheme = "Cookies";
options.Authority = "http://localhost:5000";
options.RequireHttpsMetadata = false;
options.ClientSecret = "somesecret";
options.ResponseType = "code id_token";
options.GetClaimsFromUserInfoEndpoint = true;
options.ClientId = "mvc.identity.management";
options.SaveTokens = true;
});
任何建议都会有所帮助。
【问题讨论】:
-
为什么要从身份服务器调用 API?您的用户已通过身份验证,用户应该调用 API,或者 IdentityServer,应该有自己的凭据来调用 api。
-
我在客户端调用 API
-
您的 api 代码在哪里,您的 api 需要针对身份服务器验证该令牌
-
没错,这就是问题所在,我能够从服务器获取 access_token 并设置 HttpClient 承载,但是当我尝试调用 API 而不是结果时,服务器将登录视图作为字符串返回给客户端。
-
发布您的 API 启动代码,Api 需要针对 Identity Server 验证令牌。
标签: asp.net-mvc asp.net-core asp.net-web-api2 identityserver4