You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

升级.NET 8.x时OpenIdConnect出现重定向错误,如何解决?

解决ASP.NET Core 8 Web API升级OpenIdConnect 8.0.6后重定向授权端点错误

问题描述

升级Microsoft.AspNetCore.Authentication.OpenIdConnect至8.0.6版本后,出现以下错误:

System.InvalidOperationException: Cannot redirect to the authorization endpoint, the configuration may be missing or invalid.

调用栈信息:

at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleChallengeAsyncInternal(AuthenticationProperties properties)
at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleChallengeAsync(AuthenticationProperties properties)
at Microsoft.AspNetCore.Authentication.AuthenticationHandler`1.ChallengeAsync(AuthenticationProperties properties)
at Microsoft.AspNetCore.Authentication.AuthenticationService.ChallengeAsync(HttpContext context, String scheme, AuthenticationProperties properties)
at Microsoft.AspNetCore.Authorization.Policy.AuthorizationMiddlewareResultHandler.<>c__DisplayClass0_0.<g__Handle|0>d.MoveNext()
--- End of stack trace from previous location ---
at Microsoft.AspNetCore.Authorization.AuthorizationMiddleware.Invoke(HttpContext context)
at Microsoft.AspNetCore.Authentication.AuthenticationMiddleware.Invoke(HttpContext context)

当前认证配置:

.AddOpenIdConnect(options =>
{
    options.ClientId = "{clientId}";
    options.ClientSecret = "{clientSecret}";
    options.Authority = "{authority}";

    options.ResponseType = "code";
    options.Scope.Add("role");
    options.Scope.Add("openid");
    options.Scope.Add("email");
});

解决方案

  • 验证Authority端点有效性
    确保{authority}是完整可访问的OIDC提供商地址,直接在浏览器访问{authority}/.well-known/openid-configuration,确认返回的JSON中包含authorization_endpoint字段,且该字段值有效。

  • 排查配置加载异常
    手动触发配置加载并捕获具体错误,在配置代码中添加验证逻辑:

    var configurationManager = new ConfigurationManager<OpenIdConnectConfiguration>(
        $"{options.Authority}/.well-known/openid-configuration",
        new OpenIdConnectConfigurationRetriever(),
        new HttpDocumentRetriever());
    try
    {
        var config = await configurationManager.GetConfigurationAsync(CancellationToken.None);
        // 可输出config.AuthorizationEndpoint确认是否存在
    }
    catch (Exception ex)
    {
        // 此处捕获的异常会暴露配置加载失败的真实原因(如网络、证书、端点不存在等)
    }
    
  • 检查网络与证书信任

    • 若Identity Server使用自签名证书,需确保Web API所在服务器已信任该证书,否则会导致配置加载失败。
    • 排查防火墙、代理是否阻断了Web API对Identity Server配置端点的访问。
  • 确认Client凭证有效性
    检查Identity Server端是否已正确注册该ClientId,且ClientSecret完全匹配,部分提供商要求ClientSecret进行Base64编码或特殊格式处理,需对应调整。

  • 手动指定端点(临时 workaround)
    若自动发现配置失败,可显式指定各OIDC端点:

    options.AuthorizationEndpoint = "{authority}/connect/authorize";
    options.TokenEndpoint = "{authority}/connect/token";
    options.UserInformationEndpoint = "{authority}/connect/userinfo";
    options.JwksUri = "{authority}/connect/jwks";
    

内容的提问来源于stack exchange,提问作者Tom Lee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 04:06:19