Azure AD B2C配置报错AADB2C90057:OAuth隐式流未配置求助
问题背景
按照官方文档配置Azure AD B2C示例Web应用认证,完成步骤5.3后点击“注册/登录”,出现AADB2C90057错误,提示“所提供的应用未配置为允许'OAuth'隐式流”。已在应用注册的“隐式授予和混合流”设置中开启“ID Tokens”,但问题依旧。
错误详情
Error.
An error occurred while processing your request.
Request ID: 00-7dc383f643debddd99a526855bc2dd7b-f993ccb566d654c6-00Details
Message contains error: 'unauthorized_client', error_description: 'AADB2C90057: The provided application is not configured to allow the 'OAuth' Implicit flow. Correlation ID: c2c20e32-f291-4c91-acad-c1645ef323bb Timestamp: 2024-08-19 11:51:22Z ', error_uri: 'error_uri is null'.© 2022 - WebApp_OpenIDConnect_DotNet
应用运行日志
info: Microsoft.AspNetCore.Hosting.Diagnostics[1] Request starting HTTP/2 GET https://localhost:44316/MicrosoftIdentity/Account/SignIn? - - - info: Microsoft.AspNetCore.Routing.EndpointMiddleware[0] Executing endpoint 'Microsoft.Identity.Web.UI.Areas.MicrosoftIdentity.Controllers.AccountController.SignIn (Microsoft.Identity.Web.UI)' info: Microsoft.AspNetCore.Mvc.Infrastructure.ControllerActionInvoker[102] Route matched with {area = "MicrosoftIdentity", action = "SignIn", controller = "Account", page = ""}. Executing controller action with signature Microsoft.AspNetCore.Mvc.IActionResult SignIn(System.String, System.String) on controller Microsoft.Identity.Web.UI.Areas.MicrosoftIdentity.Controllers.AccountController (Microsoft.Identity.Web.UI). info: Microsoft.AspNetCore.Mvc.ChallengeResult[1] Executing ChallengeResult with authentication schemes (OpenIdConnect). info: Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler[12] AuthenticationScheme: OpenIdConnect was challenged. info: Microsoft.AspNetCore.Mvc.Infrastructure.ControllerActionInvoker[105] Executed action Microsoft.Identity.Web.UI.Areas.MicrosoftIdentity.Controllers.AccountController.SignIn (Microsoft.Identity.Web.UI) in 339.5867ms info: Microsoft.AspNetCore.Routing.EndpointMiddleware[1] Executed endpoint 'Microsoft.Identity.Web.UI.Areas.MicrosoftIdentity.Controllers.AccountController.SignIn (Microsoft.Identity.Web.UI)' info: Microsoft.AspNetCore.Hosting.Diagnostics[2] Request finished HTTP/2 GET https://localhost:44316/MicrosoftIdentity/Account/SignIn? - 302 0 - 364.4701ms info: Microsoft.AspNetCore.Hosting.Diagnostics[1] Request starting HTTP/2 POST https://localhost:44316/signin-oidc - application/x-www-form-urlencoded 561 fail: Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler[12] Message contains error: 'unauthorized_client', error_description: 'AADB2C90057: The provided application is not configured to allow the 'OAuth' Implicit flow. Correlation ID: 0ea1fec4-a0db-4800-8eb8-7df0a6b16c41 Timestamp: 2024-08-19 11:53:15Z ', error_uri: 'error_uri is null'. info: Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler[4] Error from RemoteAuthentication: Message contains error: 'unauthorized_client', error_description: 'AADB2C90057: The provided application is not configured to allow the 'OAuth' Implicit flow. Correlation ID: 0ea1fec4-a0db-4800-8eb8-7df0a6b16c41 Timestamp: 2024-08-19 11:53:15Z ', error_uri: 'error_uri is null'.. info: Microsoft.AspNetCore.Hosting.Diagnostics[2] Request finished HTTP/2 POST https://localhost:44316/signin-oidc - 302 0 - 41.4144ms
当前配置信息
appsettings.json 内容
{ "AllowedHosts": "*", "AzureAdB2C": { "Instance": "https://xxx.b2clogin.com", "Domain": "xxx.onmicrosoft.com", "ClientId": "abc", "SignedOutCallbackPath": "/signout/B2C_1_susi", "SignUpSignInPolicyId": "B2C_1_susi", "EditProfilePolicyId": "B2C_1_edit_profile", "ResetPasswordPolicyId": "B2C_1_reset_password" //"CallbackPath": "/signin/B2C_1_sign_up_in", }, "Logging": { "LogLevel": { "Default": "Information", "Microsoft": "Warning", "Microsoft.Hosting.Lifetime": "Information" } } }
已尝试的修复操作
参考社区方案,添加以下代码并在appsettings.json中配置ClientSecret后,登录流程可正常推进,但编辑资料流程仍失败:
services.Configure<OpenIdConnectOptions>(OpenIdConnectDefaults.AuthenticationScheme, options => { options.ResponseType = OpenIdConnectResponseType.Code; options.Scope.Add(options.ClientId); });
疑问
请问该问题的原因可能是什么?
内容的提问来源于stack exchange,提问作者Alexandre Guimond

