SPA应用基于node-oidc-provider与ASP.NET Core 8 API的OIDC配置问题
问题:SPA+node-oidc-provider+.NET Core 8 API的OIDC认证配置故障
背景
- 环境:基于Angular框架的SPA(使用angular-auth-oidc-client)、新搭建的node-oidc-provider OIDC服务器、.NET Core 8 API服务器
- 现状:SPA已完成认证流程,能从OIDC服务器的
/me路由获取用户姓名等声明并展示,但所有发往API服务器的请求均被拒绝 - 细节:API控制器仅添加了
[Authorize]特性,请求全部返回401状态码;之前请求会发送以ey...开头的长JWT令牌,现在仅发送短授权码格式的Bearer Token:authorization: Bearer _nF3YnR8gOM6Zqj64_NvzgUZXXXXXXXXXXXXXXXXj,不确定是否已不再使用JWT
各端配置详情
node-oidc-provider客户端配置
clients: [ { client_id: 'xxxxx', token_endpoint_auth_method: 'none', grant_types: ['refresh_token', 'authorization_code'], redirect_uris: ['https://localhost:5003'] ... } ]
Angular AuthModule配置
AuthModule.forRoot({ config: { authority: "http://localhost:3000", redirectUrl: `${window.location.origin}/callback`, postLogoutRedirectUri: window.location.origin, clientId: 'xxxxx', scope: 'openid api1 profile offline_access', responseType: 'code', silentRenew: true, useRefreshToken: true, secureRoutes: ['https://localhost:7084/',], historyCleanupOff: true, }, }),
.NET Core Program.cs 初始配置(返回401)
builder.Services.AddAuthentication(OpenIdConnectDefaults.AuthenticationScheme).AddOpenIdConnect(options => { options.Authority = "http://localhost:3000"; options.GetClaimsFromUserInfoEndpoint = true; //added options.RequireHttpsMetadata = false; //added options.ClientId = "xxxxx"; }); //added this section builder.Services.AddAuthentication(BearerTokenDefaults.AuthenticationScheme).AddBearerToken(options => { options.ClaimsIssuer = "http://localhost:3000"; }); //removed this section builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme).AddJwtBearer(options => { options.Authority = "https://localhost:5001"; options.TokenValidationParameters.ValidateAudience = false; });
- 错误表现:所有API请求返回401,无额外错误原因信息
.NET Core Program.cs 调整后配置(返回302/303跳转)
builder.Services.AddAuthentication(options => { options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; options.DefaultChallengeScheme = OpenIdConnectDefaults.AuthenticationScheme; }) .AddOpenIdConnect(options => { options.Authority = "http://localhost:3000"; options.ClientId = "xxxxx"; options.ClientSecret = ""; options.RequireHttpsMetadata = false; options.SignInScheme = CookieAuthenticationDefaults.AuthenticationScheme; options.ResponseType = OpenIdConnectResponseType.Code; options.SaveTokens = true; options.GetClaimsFromUserInfoEndpoint = true; options.MapInboundClaims = false; options.TokenValidationParameters.NameClaimType = JwtRegisteredClaimNames.Name; options.TokenValidationParameters.RoleClaimType = "roles"; });
- 现象:API请求返回302状态码并跳转到OIDC服务器,跳转后的请求返回303状态码;已将
localhost:7084添加到node-oidc-provider的redirect_uris列表中 - 疑问:这是否属于SPA应用的正常行为?API请求能否正常返回?为何会出现303状态码?
内容的提问来源于stack exchange,提问作者Bluebaron
相关产品推荐
相关产品推荐

