You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SPA应用基于node-oidc-provider与ASP.NET Core 8 API的OIDC配置问题

问题:SPA+node-oidc-provider+.NET Core 8 API的OIDC认证配置故障

背景

  • 环境:基于Angular框架的SPA(使用angular-auth-oidc-client)、新搭建的node-oidc-provider OIDC服务器、.NET Core 8 API服务器
  • 现状:SPA已完成认证流程,能从OIDC服务器的/me路由获取用户姓名等声明并展示,但所有发往API服务器的请求均被拒绝
  • 细节:API控制器仅添加了[Authorize]特性,请求全部返回401状态码;之前请求会发送以ey...开头的长JWT令牌,现在仅发送短授权码格式的Bearer Token:authorization: Bearer _nF3YnR8gOM6Zqj64_NvzgUZXXXXXXXXXXXXXXXXj,不确定是否已不再使用JWT

各端配置详情

node-oidc-provider客户端配置

clients: [
  {
    client_id: 'xxxxx',
    token_endpoint_auth_method: 'none',
    grant_types: ['refresh_token', 'authorization_code'],
    redirect_uris: ['https://localhost:5003']
    ...
  }
]

Angular AuthModule配置

AuthModule.forRoot({
  config: {
    authority: "http://localhost:3000",
    redirectUrl: `${window.location.origin}/callback`,
    postLogoutRedirectUri: window.location.origin,
    clientId: 'xxxxx',
    scope: 'openid api1 profile offline_access',
    responseType: 'code',
    silentRenew: true,
    useRefreshToken: true,
    secureRoutes: ['https://localhost:7084/',],
    historyCleanupOff: true,
  },
}),

.NET Core Program.cs 初始配置(返回401)

builder.Services.AddAuthentication(OpenIdConnectDefaults.AuthenticationScheme).AddOpenIdConnect(options =>
{
  options.Authority = "http://localhost:3000";
  options.GetClaimsFromUserInfoEndpoint = true; //added
  options.RequireHttpsMetadata = false; //added
  options.ClientId = "xxxxx";
});

//added this section
builder.Services.AddAuthentication(BearerTokenDefaults.AuthenticationScheme).AddBearerToken(options =>
{
  options.ClaimsIssuer = "http://localhost:3000";
});

//removed this section
builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme).AddJwtBearer(options =>
{
  options.Authority = "https://localhost:5001";
  options.TokenValidationParameters.ValidateAudience = false;
});
  • 错误表现:所有API请求返回401,无额外错误原因信息

.NET Core Program.cs 调整后配置(返回302/303跳转)

builder.Services.AddAuthentication(options =>
{
  options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
  options.DefaultChallengeScheme = OpenIdConnectDefaults.AuthenticationScheme;
})
.AddOpenIdConnect(options =>
{
  options.Authority = "http://localhost:3000";
  options.ClientId = "xxxxx";
  options.ClientSecret = "";
  options.RequireHttpsMetadata = false;
  options.SignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;
  options.ResponseType = OpenIdConnectResponseType.Code;
  options.SaveTokens = true;
  options.GetClaimsFromUserInfoEndpoint = true;
  options.MapInboundClaims = false;
  options.TokenValidationParameters.NameClaimType = JwtRegisteredClaimNames.Name;
  options.TokenValidationParameters.RoleClaimType = "roles";
});
  • 现象:API请求返回302状态码并跳转到OIDC服务器,跳转后的请求返回303状态码;已将localhost:7084添加到node-oidc-provider的redirect_uris列表中
  • 疑问:这是否属于SPA应用的正常行为?API请求能否正常返回?为何会出现303状态码?

内容的提问来源于stack exchange,提问作者Bluebaron

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 04:50:56