【发布时间】:2018-12-04 19:39:08
【问题描述】:
我将身份服务器的 clients 存储在 appsettings.json 文件中:
"ClientSettings": [
{
"ClientId": "TestClient1",
"RedirectUris": [ "http://localhost:5002/signin-oidc" ],
"PostLogoutRedirectUris": [ "http://localhost:5002/signout-callback-oidc" ],
"AllowedGrantTypes": [ "hybrid" ],
"AllowedScopes": [ "openid","profile","email" ],
"RequireConsent": "false",
"Enabled": "true",
"ClientSecrets": [
{
"Description": "This is the client sceret description.",
"Value": "password123"
}
]
}
],
在我的 ConfigureServices 方法中,我设置了依赖注入
services.Configure<List<Client>>(config.GetSection("ClientSettings"));
我的IClientStore 通过依赖注入获取客户端列表。当然,我需要散列客户端密码。为了让这个问题保持简单,我编写了这段代码,假设我只有一个客户端和一个客户端密码。
public ClientConfigFileStore(IOptions<List<Client>> options)
{
var jsonClient = options.Value[0];
Client client = new Client()
{
ClientId = jsonClient.ClientId,
RedirectUris = jsonClient.RedirectUris,
PostLogoutRedirectUris = jsonClient.PostLogoutRedirectUris,
AllowedGrantTypes = jsonClient.AllowedGrantTypes,
AllowedScopes = jsonClient.AllowedScopes,
RequireConsent = jsonClient.RequireConsent,
Enabled = jsonClient.Enabled,
};//Works
Client client = jsonClient;//Does not work
client.ClientSecrets = new List<Secret>()
{
new Secret(jsonClient.ClientSecrets.First().Value.Sha256())
};
clients = new List<Client>() { client };
}
不知何故,我需要创建Client 的新实例,并且使用依赖注入创建的实例不起作用。用户在身份服务器上输入他的凭据后,重定向回客户端失败并显示Client secret validation failed for the client: TestClient1
为什么需要创建一个新实例,是否有更优雅的方式从appsettings.json 文件加载客户端?
【问题讨论】:
-
你为什么要从那个文件中加载它们?为什么不给它自己的文件呢?
-
我也可以这样做,而且会更有条理。但这并不能解决问题?
-
你为什么不只使用 AddInMemoryClients?我想我不明白你为什么要这样做,你到底想做什么。
-
我想要一种简单的方法来调整客户端设置。在使用
AddInMemoryClients时调整设置时,需要发布新版本的身份服务器。 -
这就是它的工作原理。我认为您不能即时将新客户端添加到内存中。如果您希望能够像这样添加它们,您应该将它们放在数据库中。我将深入研究代码,看看是否有办法在运行中添加内存客户端。
标签: c# authentication asp.net-core dependency-injection identityserver4