You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Token请求失败返回invalid grant错误,用户被禁用问题排查

Token请求返回"invalid grant"错误,日志提示用户已被禁用

请求Token时失败,返回invalid grant错误,IdentityServer日志内容如下:

2024-07-04 21:06:57.551 -04:00 [DBG] Start key discovery request
2024-07-04 21:06:57.552 -04:00 [INF] Request finished HTTP/1.1 GET https://localhost:44322/.well-known/openid-configuration/jwks - 200 null application/json; charset=UTF-8 4.6024ms
2024-07-04 21:07:02.605 -04:00 [INF] Request starting HTTP/1.1 POST https://localhost:44322/connect/token - application/x-www-form-urlencoded 63
2024-07-04 21:07:02.606 -04:00 [DBG] AuthenticationScheme: idsrv was not authenticated.
2024-07-04 21:07:02.606 -04:00 [DBG] AuthenticationScheme: idsrv was not authenticated.
2024-07-04 21:07:02.606 -04:00 [DBG] Request path /connect/token matched to endpoint type Token
2024-07-04 21:07:02.610 -04:00 [DBG] Endpoint enabled: Token, successfully created handler: IdentityServer4.Endpoints.TokenEndpoint
2024-07-04 21:07:02.610 -04:00 [INF] Invoking IdentityServer endpoint: IdentityServer4.Endpoints.TokenEndpoint for /connect/token
2024-07-04 21:07:02.610 -04:00 [DBG] Start token request.
2024-07-04 21:07:02.610 -04:00 [DBG] Start client validation
2024-07-04 21:07:02.610 -04:00 [DBG] Start parsing Basic Authentication secret
2024-07-04 21:07:02.611 -04:00 [DBG] Parser found secret: BasicAuthenticationSecretParser
2024-07-04 21:07:02.611 -04:00 [DBG] Secret id found: ro.client
2024-07-04 21:07:02.611 -04:00 [DBG] client configuration validation for client ro.client succeeded.
2024-07-04 21:07:02.611 -04:00 [DBG] Secret validator success: HashedSharedSecretValidator
2024-07-04 21:07:02.611 -04:00 [DBG] Client validation success
2024-07-04 21:07:02.612 -04:00 [DBG] Start token request validation
2024-07-04 21:07:02.613 -04:00 [DBG] Start resource owner password token request validation
2024-07-04 21:07:13.898 -04:00 [DBG] IsActive called from: ResourceOwnerValidation
2024-07-04 21:07:13.900 -04:00 [ERR] User has been disabled

测试用户在Config.cs中的配置代码如下:

public static List<TestUser> GetUsers()
{
    return new List<TestUser>
    {
        new TestUser
        {
            SubjectId = "1",
            Username = "alice",
            Password = "password"

        },
        new TestUser
        {
            SubjectId = "2",
            Username = "bob",
            Password = "password"
        }
    };
}

已确认客户端配置正确,验证器验证通过,但日志明确提示User has been disabled。TestUser默认应为活跃状态,未找到调用栈中设置用户禁用的位置,求指出问题所在。

内容的提问来源于stack exchange,提问作者Matt Perejda

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 08:35:07