You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Bicep配置App Service的OpenID Connect认证遇阻求助

用Bicep配置App Service对接Identity Server的OpenID Connect认证

下面是一套可直接复用的Bicep配置示例,针对对接Identity Server的场景做了适配:

// 引用已存在的App Service
resource appService 'Microsoft.Web/sites@2023-01-01' existing = {
  name: 'your-app-service-name'
}

// 配置Auth Settings V2
resource authSettingsV2 'Microsoft.Web/sites/config@2023-01-01' = {
  parent: appService
  name: 'authsettingsV2'
  properties: {
    isAuthEnabled: true
    identityProviders: {
      customOpenIdConnectProviders: {
        // 自定义Provider标识,后续登录路由会用到这个名称
        'IdentityServer': {
          registration: {
            clientId: 'your-identity-server-client-id'
            clientCredential: {
              // 引用App Service配置中存储密钥的应用设置名称,避免硬编码
              clientSecretSettingName: 'IDENTITY_SERVER_CLIENT_SECRET'
            }
            openIdConnectConfiguration: {
              authorizationEndpoint: 'https://your-identity-server-domain/connect/authorize'
              tokenEndpoint: 'https://your-identity-server-domain/connect/token'
              issuer: 'https://your-identity-server-domain'
              jwksUri: 'https://your-identity-server-domain/.well-known/openid-configuration/jwks'
            }
          }
          login: {
            nameClaimType: 'name' // 指定用于用户名展示的Claim字段
            scopes: [
              'openid'
              'profile'
              'email' // 根据业务需求添加所需Scope
            ]
          }
        }
      }
    }
    login: {
      routes: {
        // 默认登录路由,指向自定义的Provider
        loginRoute: '/.auth/login/IdentityServer'
      }
    }
    httpSettings: {
      requireHttps: true
      forwardProxy: {
        convention: 'NoProxy'
      }
    }
  }
}

关键配置说明

  • customOpenIdConnectProviders的键名:比如示例中的IdentityServer,这个名称是自定义标识,会对应到登录路由/.auth/login/[ProviderName],同时要和顶层login.routes.loginRoute中的名称保持一致。
  • registration区块:
    • clientId必须和Identity Server中注册的客户端ID完全匹配。
    • clientSecretSettingName不要直接写明文密钥,而是引用App Service应用设置里的密钥名称(需要提前在App Service的配置面板添加该密钥)。
    • openIdConnectConfiguration中的端点地址,可从Identity Server的/.well-known/openid-configuration元数据接口获取,确保地址准确。
  • login区块:scopes至少要包含openid,其他Scope根据业务需求添加;nameClaimType对应Identity Server返回的用户名称Claim,默认是name。

额外注意事项

  • 需在Identity Server的客户端配置中,添加App Service的回调地址:https://<你的App Service域名>.azurewebsites.net/.auth/login/IdentityServer/callback。
  • 部署前可通过访问Identity Server的元数据接口,验证authorizationEndpoint、tokenEndpoint等地址的有效性。

内容的提问来源于stack exchange,提问作者Moelbeck

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 16:30:02