【问题标题】:Cannot use refresh token to obtain new access token and refresh token in Identity Server 3 implementation在 Identity Server 3 实现中无法使用刷新令牌来获取新的访问令牌和刷新令牌
【发布时间】:2016-11-21 15:39:43
【问题描述】:

我一直在使用 Thinktecture 的身份服务器,现在尝试访问刷新令牌端点时遇到了一些问题。

我只有几个这样配置的客户端:

授权码流客户端:

新客户

{
    ClientId = "tripgalleryauthcode",
    ClientName = "Trip Gallery (Authorization Code)",
    Flow = Flows.AuthorizationCode, 
    AllowAccessToAllScopes = true,
    RequireConsent = false,

    RedirectUris = new List<string>
    {
        "redirecturi"
    },           

     ClientSecrets = new List<Secret>()
    {
        new Secret("somesecret".Sha256())
    }                    
}

混合流客户端:

new Client 
{
    ClientId = "tripgalleryhybrid",
    ClientName = "Tripgalleryhybrid (Hybrid)",
    Flow = Flows.Hybrid, 
    AllowAccessToAllScopes = true,

    RequireConsent = false,

    IdentityTokenLifetime = 10,
    AccessTokenLifetime = 120,

    // redirect = URI of the MVC application
    RedirectUris = new List<string>
    {
        "redirecturi"
    },

    // Needed when requesting refresh tokens
    ClientSecrets = new List<Secret>()
    {
        new Secret("somesecret".Sha256())
    },
    PostLogoutRedirectUris = new List<string>()
    {
        "postlogouturi"
    }
}

我所做的是,我有使用混合流的 ASP.NET MVC 客户端。身份验证后,我收到访问令牌、刷新令牌和其他一些东西。

我要做的是测试刷新令牌端点。我准备请求的方式如下:

我向 /identity/connect/revocation 发出 POST 请求 在我的请求标题中:

  • 内容类型:application/x-www-form-urlencoded
  • 授权:基本 dHJpcGdhbGxlcnlhdXRoY29kZTpteXJhbmRvbWNsaWVudHNlY3JldA==(这是 base64 编码的 clientid:clientsecret 是我的授权码)

在我的请求正文中:token=0a24f80dcc97a56ede0e7c04563a3493&token_type_hint=refresh_token

令牌是我通过混合客户端进行身份验证后获得的令牌。

当我触发请求时,它返回 Http 200。但没有返回任何内容。当我查看身份服务器日志时,我看到的是:

SnapshotHelper::TakeSnapshotTimerCallback
SnapshotHelper::TakeSnapshotInternal - no new files in CodeGen
w3wp.exe Warning: 0 : 2016-11-13 13:54:11.557 +00:00 [Warning] AuthorizationCodeStore not configured - falling back to InMemory
w3wp.exe Warning: 0 : 2016-11-13 13:54:11.620 +00:00 [Warning] TokenHandleStore not configured - falling back to InMemory
w3wp.exe Warning: 0 : 2016-11-13 13:54:11.620 +00:00 [Warning] ConsentStore not configured - falling back to InMemory
w3wp.exe Warning: 0 : 2016-11-13 13:54:11.620 +00:00 [Warning] RefreshTokenStore not configured - falling back to InMemory
w3wp.exe Information: 0 : 2016-11-13 13:54:12.356 +00:00 [Information] Start token revocation request
w3wp.exe Information: 0 : 2016-11-13 13:54:12.401 +00:00 [Information] Client secret id found: "tripgalleryauthcode"
w3wp.exe Information: 0 : 2016-11-13 13:54:12.401 +00:00 [Information] Client validation success
w3wp.exe Information: 0 : 2016-11-13 13:54:12.401 +00:00 [Information] End token revocation request

我真正期望至少获得新的访问权限和刷新令牌,但什么也没有。我想我在客户端的配置中确实遗漏了一些东西,所以如果你能帮助我,我会很高兴。

编辑:

我将端点更改为:/identity/connect/token,并将请求正文更改为: grant_type=refresh_token&token=635c7cbcfa1c0417b6d574ade388c0d8&token_type_hint=refresh_token 但仍然没有成功。现在我的身份服务器日志显示:

SnapshotHelper::TakeSnapshotTimerCallback
SnapshotHelper::TakeSnapshotInternal - no new files in CodeGen
SnapshotHelper::TakeSnapshot time since last: 00:19:59.9992231
w3wp.exe Information: 0 : 2016-11-13 20:40:33.406 +00:00 [Information] Start token request
w3wp.exe Information: 0 : 2016-11-13 20:40:33.406 +00:00 [Information] Client secret id found: "tripgalleryauthcode"
w3wp.exe Information: 0 : 2016-11-13 20:40:33.406 +00:00 [Information] Client validation success
w3wp.exe Information: 0 : 2016-11-13 20:40:33.406 +00:00 [Information] Start token request validation
w3wp.exe Information: 0 : 2016-11-13 20:40:33.406 +00:00 [Information] Start validation of refresh token request
w3wp.exe Error: 0 : 2016-11-13 20:40:33.406 +00:00 [Error] "Refresh token is missing"
 "{
  \"ClientId\": \"tripgalleryauthcode\",
  \"ClientName\": \"Trip Gallery (Authorization Code)\",
  \"GrantType\": \"refresh_token\",
  \"Raw\": {
    \"grant_type\": \"refresh_token\",
    \"token\": \"635c7cbcfa1c0417b6d574ade388c0d8\",
    \"token_type_hint\": \"refresh_token\"
  }
}"
w3wp.exe Information: 0 : 2016-11-13 20:40:33.406 +00:00 [Information] End token request
w3wp.exe Information: 0 : 2016-11-13 20:40:33.406 +00:00 [Information] Returning error: invalid_request

第二次编辑:

根据此处发布的文档:Token Endpoint 以及此处的内容:TokenRequest 以及与我提出此请求相关的更多资源:

我认为这是正确的。不幸的是,我仍然从身份服务器获取 HTTP 400,并显示错误:error=invalid_grant。这让我觉得很可能我必须在我的客户端上进行更多配置。在互联网上的一些示例中,我可以看到配置客户端时的用法:AbsoluteRefreshTokenLifetime、SlidingRefreshTokenLifetime、RefreshTokenUsage、RefreshTokenExpiration。请您至少给我一个深入研究的方向吗?

解决方案:

对我有用的是将这些选项添加到客户端: // 刷新令牌选项

AccessTokenType = AccessTokenType.Jwt,
AccessTokenLifetime = 3600,
RefreshTokenUsage = TokenUsage.ReUse,
RefreshTokenExpiration = TokenExpiration.Absolute,
AbsoluteRefreshTokenLifetime = 1296000

【问题讨论】:

  • 谢谢,您的解决方案帮助我解决了我的问题。

标签: identityserver3 thinktecture-ident-server


【解决方案1】:

您正在使用撤销端点,它允许您销毁(也称为“撤销”)令牌。要使用刷新令牌获取新的访问令牌,您需要具有 grant_type=refresh_token 的令牌端点,如文档中所述:https://identityserver.github.io/Documentation/docsv2/endpoints/token.html

【讨论】:

  • 非常感谢您的回答!我只是更改了端点并稍微修改了 POST 正文,但仍然没有得到任何有价值的响应。我已经编辑了我的帖子,你可以看到现在我收到了 invalid_request。
  • 我确实做到了,但仍然不知道为什么它不起作用。我认为我的编辑必须完成这项工作。我试过这样的身体:grant_type=refresh_token&refresh_token=23988f082daf7bd88a3facabe54fc8d7 仍然没有。我尝试在标题和帖子正文上添加客户端 ID 和客户端密码,但仍然相同。除了端点地址的错误之外,这里肯定有一个更普遍的错误。
  • 我对我的帖子进行了另一次编辑,我认为这是调用令牌端点的正确方法。我真的把所有的文档都读了好几遍,没有别的我能想到的。你能给我指出一个深入研究的方向吗?
猜你喜欢
  • 1970-01-01
  • 2013-08-23
  • 1970-01-01
  • 2020-06-12
  • 2020-11-09
  • 2015-07-19
  • 2019-06-29
  • 2022-01-23
  • 2019-10-26
相关资源
最近更新 更多