【问题标题】:IdentityServer4 and Getting Multiple Applications to Share AuthenticationIdentityServer4 和让多个应用程序共享身份验证
【发布时间】:2020-03-07 17:35:48
【问题描述】:

在使用身份服务器实现单点登录或类似功能的不同示例中,我遇到了很多麻烦。给定

的 IDServ Startup.cs 配置
var builder = services.AddIdentityServer()
                .AddInMemoryIdentityResources(Config.GetIdentityResources())
                .AddInMemoryApiResources(Config.GetApis())
                .AddInMemoryClients(Config.GetClients())
                .AddTestUsers(Config.GetUsers());

还有两个客户:

services.AddMvc();

            JwtSecurityTokenHandler.DefaultInboundClaimTypeMap.Clear();

            services.AddAuthentication(options =>
                {
                    options.DefaultScheme = "Cookies";
                    options.DefaultChallengeScheme = "oidc";
                })
                .AddCookie("Cookies")
                .AddOpenIdConnect("oidc", options =>
                {
                    options.Authority = "http://localhost:5000";
                    options.RequireHttpsMetadata = false;

                    options.ClientId = "mvc";
                    options.SaveTokens = true;
                });

+

services.AddMvcCore()
                .AddAuthorization()
                .AddJsonFormatters();

            services.AddAuthentication("Bearer")
                .AddJwtBearer("Bearer", options =>
                {
                    options.Authority = "http://localhost:5000";
                    options.RequireHttpsMetadata = false;

                    options.Audience = "api1";
                });

当请求尚未附带有效令牌时,我总是会遇到让第二个客户端重定向到 Auth 服务器的问题。我已经给出了上面的例子,但它似乎仍然存在于 client2 是否像第一个那样具有AddCookie,或者它们中的一个或两个是否使用AddJwtBearer,等等。经过几天的不同组合config 我觉得有必要问一下配置的重要部分是什么导致客户端重定向到 IdentityServer 的身份验证/登录页面,以及如何让多个客户端在彼此之间共享 Auth 时玩得很好。

我找到了 IdentityServer 规范示例 (https://github.com/IdentityServer/IdentityServer4/tree/aspnetcore2/samples/Quickstarts/),但它们并没有很好地涵盖这一点:如上面的示例(我从 QS #3 中获取了 sn-ps,只有第一个客户端重定向,如果它还没有有效的不记名令牌,则第二个将只是 401。

【问题讨论】:

    标签: asp.net-core single-sign-on identityserver4


    【解决方案1】:

    根据您的代码,第一件事是您在 IdentityServer4 中使用 AddOpenIdConnect 配置了一个客户端。

    您提到的第二个客户是 IDS 的 API 资源/受众。哪个通过AddOpenIdConnect 提到的客户端的令牌进行身份验证。

    您最好查看以下示例。 http://docs.identityserver.io/en/latest/quickstarts/3_aspnetcore_and_apis.html

    【讨论】:

      猜你喜欢
      • 2013-08-16
      • 1970-01-01
      • 1970-01-01
      • 2011-01-17
      • 1970-01-01
      • 2015-08-14
      • 2011-05-01
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多