通过Bicep配置App Service的OpenID Connect认证遇阻求助
用Bicep配置App Service对接Identity Server的OpenID Connect认证
下面是一套可直接复用的Bicep配置示例,针对对接Identity Server的场景做了适配:
// 引用已存在的App Service resource appService 'Microsoft.Web/sites@2023-01-01' existing = { name: 'your-app-service-name' } // 配置Auth Settings V2 resource authSettingsV2 'Microsoft.Web/sites/config@2023-01-01' = { parent: appService name: 'authsettingsV2' properties: { isAuthEnabled: true identityProviders: { customOpenIdConnectProviders: { // 自定义Provider标识,后续登录路由会用到这个名称 'IdentityServer': { registration: { clientId: 'your-identity-server-client-id' clientCredential: { // 引用App Service配置中存储密钥的应用设置名称,避免硬编码 clientSecretSettingName: 'IDENTITY_SERVER_CLIENT_SECRET' } openIdConnectConfiguration: { authorizationEndpoint: 'https://your-identity-server-domain/connect/authorize' tokenEndpoint: 'https://your-identity-server-domain/connect/token' issuer: 'https://your-identity-server-domain' jwksUri: 'https://your-identity-server-domain/.well-known/openid-configuration/jwks' } } login: { nameClaimType: 'name' // 指定用于用户名展示的Claim字段 scopes: [ 'openid' 'profile' 'email' // 根据业务需求添加所需Scope ] } } } } login: { routes: { // 默认登录路由,指向自定义的Provider loginRoute: '/.auth/login/IdentityServer' } } httpSettings: { requireHttps: true forwardProxy: { convention: 'NoProxy' } } } }
关键配置说明
- customOpenIdConnectProviders的键名:比如示例中的
IdentityServer,这个名称是自定义标识,会对应到登录路由/.auth/login/[ProviderName],同时要和顶层login.routes.loginRoute中的名称保持一致。 - registration区块:
clientId必须和Identity Server中注册的客户端ID完全匹配。clientSecretSettingName不要直接写明文密钥,而是引用App Service应用设置里的密钥名称(需要提前在App Service的配置面板添加该密钥)。openIdConnectConfiguration中的端点地址,可从Identity Server的/.well-known/openid-configuration元数据接口获取,确保地址准确。
- login区块:
scopes至少要包含openid,其他Scope根据业务需求添加;nameClaimType对应Identity Server返回的用户名称Claim,默认是name。
额外注意事项
- 需在Identity Server的客户端配置中,添加App Service的回调地址:
https://<你的App Service域名>.azurewebsites.net/.auth/login/IdentityServer/callback。 - 部署前可通过访问Identity Server的元数据接口,验证
authorizationEndpoint、tokenEndpoint等地址的有效性。
内容的提问来源于stack exchange,提问作者Moelbeck
相关产品推荐
相关产品推荐

