升级.NET 8.x时OpenIdConnect出现重定向错误,如何解决?
解决ASP.NET Core 8 Web API升级OpenIdConnect 8.0.6后重定向授权端点错误
问题描述
升级Microsoft.AspNetCore.Authentication.OpenIdConnect至8.0.6版本后,出现以下错误:
System.InvalidOperationException: Cannot redirect to the authorization endpoint, the configuration may be missing or invalid.
调用栈信息:
at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleChallengeAsyncInternal(AuthenticationProperties properties) at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleChallengeAsync(AuthenticationProperties properties) at Microsoft.AspNetCore.Authentication.AuthenticationHandler`1.ChallengeAsync(AuthenticationProperties properties) at Microsoft.AspNetCore.Authentication.AuthenticationService.ChallengeAsync(HttpContext context, String scheme, AuthenticationProperties properties) at Microsoft.AspNetCore.Authorization.Policy.AuthorizationMiddlewareResultHandler.<>c__DisplayClass0_0.<g__Handle|0>d.MoveNext() --- End of stack trace from previous location --- at Microsoft.AspNetCore.Authorization.AuthorizationMiddleware.Invoke(HttpContext context) at Microsoft.AspNetCore.Authentication.AuthenticationMiddleware.Invoke(HttpContext context)
当前认证配置:
.AddOpenIdConnect(options => { options.ClientId = "{clientId}"; options.ClientSecret = "{clientSecret}"; options.Authority = "{authority}"; options.ResponseType = "code"; options.Scope.Add("role"); options.Scope.Add("openid"); options.Scope.Add("email"); });
解决方案
验证Authority端点有效性
确保{authority}是完整可访问的OIDC提供商地址,直接在浏览器访问{authority}/.well-known/openid-configuration,确认返回的JSON中包含authorization_endpoint字段,且该字段值有效。排查配置加载异常
手动触发配置加载并捕获具体错误,在配置代码中添加验证逻辑:var configurationManager = new ConfigurationManager<OpenIdConnectConfiguration>( $"{options.Authority}/.well-known/openid-configuration", new OpenIdConnectConfigurationRetriever(), new HttpDocumentRetriever()); try { var config = await configurationManager.GetConfigurationAsync(CancellationToken.None); // 可输出config.AuthorizationEndpoint确认是否存在 } catch (Exception ex) { // 此处捕获的异常会暴露配置加载失败的真实原因(如网络、证书、端点不存在等) }检查网络与证书信任
- 若Identity Server使用自签名证书,需确保Web API所在服务器已信任该证书,否则会导致配置加载失败。
- 排查防火墙、代理是否阻断了Web API对Identity Server配置端点的访问。
确认Client凭证有效性
检查Identity Server端是否已正确注册该ClientId,且ClientSecret完全匹配,部分提供商要求ClientSecret进行Base64编码或特殊格式处理,需对应调整。手动指定端点(临时 workaround)
若自动发现配置失败,可显式指定各OIDC端点:options.AuthorizationEndpoint = "{authority}/connect/authorize"; options.TokenEndpoint = "{authority}/connect/token"; options.UserInformationEndpoint = "{authority}/connect/userinfo"; options.JwksUri = "{authority}/connect/jwks";
内容的提问来源于stack exchange,提问作者Tom Lee
相关产品推荐
相关产品推荐

