Authorization Code流程浏览器可用但Postman无法正常运行问题
OpenIdDict授权码流程:Postman无法正常调用受保护接口的问题解决
问题背景
我搭建了基于OpenIdDict的认证服务器(AuthServer)和客户端应用(ClientApp),客户端配置了授权码流程,对应的控制器动作在浏览器中能正常访问,但在Postman里无法通过授权验证。
客户端配置代码
Startup.cs 认证配置
builder.Services .AddAuthentication(o => { o.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; }) .AddCookie() .AddOAuth("OpenIddict.Server.AspNetCore", o => { o.AuthorizationEndpoint = new Uri($"{AuthenticationServerUrl}connect/authorize").AbsoluteUri; o.TokenEndpoint = new Uri($"{AuthenticationServerUrl}connect/token").AbsoluteUri; o.ClientId = "testoauth"; o.ClientSecret = "testsecret"; o.CallbackPath = new PathString("/callback/login/local"); o.UsePkce = true; });
客户端控制器动作
[HttpGet("oauth")] [Authorize(AuthenticationSchemes = "OpenIddict.Server.AspNetCore")] public IActionResult OAuth2() => Ok($"Successfully authorized with authorizationcode flow.");
排查结果
- 浏览器中正常生成
.AspNetCore.Identity.ApplicationCookie,请求能通过授权验证; - Postman中虽然能成功获取
access_token,但不会自动生成并添加.AspNetCore.Identity.ApplicationCookie到请求中,导致接口调用失败。
解决方案
Postman不会自动将授权流程中生成的Cookie添加到请求头,需手动操作:
- 完成授权码流程获取
access_token后,打开Postman控制台; - 在控制台中找到
.AspNetCore.Identity.ApplicationCookie; - 将该Cookie手动添加到目标接口请求的Cookie集合中;
- 重新发起请求,即可正常调用受保护的控制器动作。
内容的提问来源于stack exchange,提问作者Christiaan
相关产品推荐
相关产品推荐

