Dot Net Core集成WSO2 IS 5.11 SSO登出报错:登出后URI不匹配
问题描述
在.NET Core Web应用中集成WSO2 Identity Server 5.11实现SSO,登录功能正常,但登出时触发错误:
"Post logout URI does not match with registered callback URI."
已反复核对URL并调整Identity Server配置,仍无法完成登出。
相关代码
Startup.cs 认证配置
services.AddAuthentication(options => { options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; options.DefaultChallengeScheme = OpenIdConnectDefaults.AuthenticationScheme; }).AddCookie(CookieAuthenticationDefaults.AuthenticationScheme) .AddOpenIdConnect(OpenIdConnectDefaults.AuthenticationScheme, options => { options.CallbackPath = "/home/index"; options.RequireHttpsMetadata = false; options.MetadataAddress = _configuration["Idp:Address"] + _configuration["Idp:MetadataAddress"]; options.SignInScheme = CookieAuthenticationDefaults.AuthenticationScheme; options.ClientId = _configuration["Idp:ClientId"]; options.ClientSecret = _configuration["Idp:ClientSecret"]; options.ResponseType = "code"; options.SaveTokens = true; options.SkipUnrecognizedRequests = true; options.UsePkce = true; options.Scope.Add("openid"); options.Scope.Add("profile"); options.Scope.Add("email"); options.Scope.Add("address"); options.Scope.Add("phone"); options.BackchannelHttpHandler = _handler; });
控制器Logout方法
public async Task<IActionResult> Logout() { return SignOut(new AuthenticationProperties { RedirectUri = "https://localhost:5001/home/index" }, CookieAuthenticationDefaults.AuthenticationScheme, OpenIdConnectDefaults.AuthenticationScheme); }
排查建议
- 核对WSO2 IS客户端登出回调配置:在WSO2 Identity Server的客户端配置页面,
Logout Callback URL必须与代码中RedirectUri完全一致,包括协议(http/https)、域名、端口、路径,注意大小写和末尾是否带斜杠。 - 显式配置PostLogoutRedirectUri:在Startup的AddOpenIdConnect配置中添加
options.PostLogoutRedirectUri = "https://localhost:5001/home/index",确保WSO2端与应用端的登出回调地址完全匹配。 - 验证元数据地址有效性:确认
MetadataAddress指向的WSO2元数据内容正确,若存在缓存问题,可清除应用缓存后重启服务,避免旧配置干扰。 - 检查URI编码问题:确保传递给WSO2的登出回调URI未被错误编码,导致匹配失败。
- 确认Allowed Origins配置:若应用与WSO2存在跨域场景,需在WSO2客户端配置中添加应用的Origin地址,避免跨域限制影响登出回调流程。
内容的提问来源于stack exchange,提问作者kartoos khan
相关产品推荐
相关产品推荐

