【发布时间】:2020-03-07 17:35:48
【问题描述】:
在使用身份服务器实现单点登录或类似功能的不同示例中,我遇到了很多麻烦。给定
的 IDServ Startup.cs 配置var builder = services.AddIdentityServer()
.AddInMemoryIdentityResources(Config.GetIdentityResources())
.AddInMemoryApiResources(Config.GetApis())
.AddInMemoryClients(Config.GetClients())
.AddTestUsers(Config.GetUsers());
还有两个客户:
services.AddMvc();
JwtSecurityTokenHandler.DefaultInboundClaimTypeMap.Clear();
services.AddAuthentication(options =>
{
options.DefaultScheme = "Cookies";
options.DefaultChallengeScheme = "oidc";
})
.AddCookie("Cookies")
.AddOpenIdConnect("oidc", options =>
{
options.Authority = "http://localhost:5000";
options.RequireHttpsMetadata = false;
options.ClientId = "mvc";
options.SaveTokens = true;
});
+
services.AddMvcCore()
.AddAuthorization()
.AddJsonFormatters();
services.AddAuthentication("Bearer")
.AddJwtBearer("Bearer", options =>
{
options.Authority = "http://localhost:5000";
options.RequireHttpsMetadata = false;
options.Audience = "api1";
});
当请求尚未附带有效令牌时,我总是会遇到让第二个客户端重定向到 Auth 服务器的问题。我已经给出了上面的例子,但它似乎仍然存在于 client2 是否像第一个那样具有AddCookie,或者它们中的一个或两个是否使用AddJwtBearer,等等。经过几天的不同组合config 我觉得有必要问一下配置的重要部分是什么导致客户端重定向到 IdentityServer 的身份验证/登录页面,以及如何让多个客户端在彼此之间共享 Auth 时玩得很好。
我找到了 IdentityServer 规范示例 (https://github.com/IdentityServer/IdentityServer4/tree/aspnetcore2/samples/Quickstarts/),但它们并没有很好地涵盖这一点:如上面的示例(我从 QS #3 中获取了 sn-ps,只有第一个客户端重定向,如果它还没有有效的不记名令牌,则第二个将只是 401。
【问题讨论】:
标签: asp.net-core single-sign-on identityserver4