You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Authorization Code流程浏览器可用但Postman无法正常运行问题

OpenIdDict授权码流程:Postman无法正常调用受保护接口的问题解决

问题背景

我搭建了基于OpenIdDict的认证服务器(AuthServer)和客户端应用(ClientApp),客户端配置了授权码流程,对应的控制器动作在浏览器中能正常访问,但在Postman里无法通过授权验证。

客户端配置代码

Startup.cs 认证配置

builder.Services
  .AddAuthentication(o => { o.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; })
  .AddCookie()
  .AddOAuth("OpenIddict.Server.AspNetCore", o => { 
    o.AuthorizationEndpoint = new Uri($"{AuthenticationServerUrl}connect/authorize").AbsoluteUri;
    o.TokenEndpoint = new Uri($"{AuthenticationServerUrl}connect/token").AbsoluteUri;
    o.ClientId = "testoauth";
    o.ClientSecret = "testsecret";
    o.CallbackPath = new PathString("/callback/login/local");
    o.UsePkce = true;
  });

客户端控制器动作

[HttpGet("oauth")]
[Authorize(AuthenticationSchemes = "OpenIddict.Server.AspNetCore")]
public IActionResult OAuth2() => Ok($"Successfully authorized with authorizationcode flow.");

排查结果

  • 浏览器中正常生成.AspNetCore.Identity.Application Cookie,请求能通过授权验证;
  • Postman中虽然能成功获取access_token,但不会自动生成并添加.AspNetCore.Identity.Application Cookie到请求中,导致接口调用失败。

解决方案

Postman不会自动将授权流程中生成的Cookie添加到请求头,需手动操作:

  1. 完成授权码流程获取access_token后,打开Postman控制台;
  2. 在控制台中找到.AspNetCore.Identity.Application Cookie;
  3. 将该Cookie手动添加到目标接口请求的Cookie集合中;
  4. 重新发起请求,即可正常调用受保护的控制器动作。

内容的提问来源于stack exchange,提问作者Christiaan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 22:24:55