You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenId Connect集成Swagger UI异常:授权框空白问题排查

Swagger UI OIDC授权框空白问题排查及修复

我已为API添加如下认证代码,可通过Postman正常访问资源,但在Swagger UI中配置OpenId Connect认证后仅显示空白授权框,请问是否遗漏配置或操作有误?

现有代码配置

认证服务配置

services.AddAuthentication(options => {
                options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
                options.DefaultChallengeScheme = OpenIdConnectDefaults.AuthenticationScheme;
            }).AddCookie(CookieAuthenticationDefaults.AuthenticationScheme, options => {
                options.Cookie.Name = "CookiE2";
            })
            .AddOpenIdConnect(OpenIdConnectDefaults.AuthenticationScheme,options => {
                options.SignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;
                options.Authority = "https://localhost:5002/";
                options.ClientId = "tapioauth";
                options.ClientSecret = "secret2";
                options.ResponseType = "code";
                options.Scope.Add("roles");
                options.Scope.Add("galleryapi.fullaccess");
                options.SaveTokens = true;
                options.ClaimActions.MapJsonKey("role","role");
            });

SwaggerGen配置

services.AddSwaggerGen(c =>
            {
                c.SwaggerDoc("v1", new OpenApiInfo { Title = "API", Version = "v1" });

                c.AddSecurityDefinition("Auth", new OpenApiSecurityScheme{
                    Type = SecuritySchemeType.OpenIdConnect,
                    Scheme = "openIdConnect",
                    Name = "OpenID Connect",
                    Description = "OpenID Connect Authentication",
                    OpenIdConnectUrl = new Uri("https://localhost:5002/.well-known/openid-configuration"), 
    
                });

                c.AddSecurityRequirement(new OpenApiSecurityRequirement
                {
                    {
                        new OpenApiSecurityScheme
                        {
                            Reference = new OpenApiReference
                            {
                                Type = ReferenceType.SecurityScheme,
                                Id = "Auth"
                            }
                        },
                        new List<string>()
                    }
                });
            });

SwaggerUI配置

app.UseSwaggerUI(c => 
                {
                    c.SwaggerEndpoint("/swagger/v1/swagger.json", "API v1");
                    //c.SwaggerEndpoint("/swagger/v2/swagger.json", "API v2");
                    c.RoutePrefix = string.Empty;
                });

问题原因及修复方案

1. SwaggerUI缺少OIDC客户端参数配置

当前SwaggerUI未配置OIDC客户端的关键参数,导致无法正确发起认证请求。更新UseSwaggerUI配置:

app.UseSwaggerUI(c => 
{
    c.SwaggerEndpoint("/swagger/v1/swagger.json", "API v1");
    c.RoutePrefix = string.Empty;
    // 添加OIDC认证所需的客户端配置
    c.OAuthClientId("tapioauth");
    c.OAuthClientSecret("secret2");
    c.OAuthAppName("API Swagger UI");
    c.OAuthUsePkce(); // 配合code流程启用PKCE,提升安全性
});

2. SecurityDefinition缺少授权流程配置

现有的AddSecurityDefinition未明确指定授权流程细节,Swagger无法识别认证方式。补充Flows配置:

c.AddSecurityDefinition("Auth", new OpenApiSecurityScheme{
    Type = SecuritySchemeType.OpenIdConnect,
    Scheme = "openIdConnect",
    Name = "OpenID Connect",
    Description = "OpenID Connect Authentication",
    OpenIdConnectUrl = new Uri("https://localhost:5002/.well-known/openid-configuration"),
    // 补充授权码流程的具体配置
    Flows = new OpenApiOAuthFlows
    {
        AuthorizationCode = new OpenApiOAuthFlow
        {
            AuthorizationUrl = new Uri("https://localhost:5002/connect/authorize"),
            TokenUrl = new Uri("https://localhost:5002/connect/token"),
            Scopes = new Dictionary<string, string>
            {
                { "roles", "角色权限" },
                { "galleryapi.fullaccess", "API完全访问权限" }
            }
        }
    }
});

3. 验证OIDC元数据端点可用性

确保https://localhost:5002/.well-known/openid-configuration可以正常访问并返回合法的OIDC元数据。如果该端点不可达,SwaggerUI无法加载认证配置,会导致授权框空白。

4. 检查中间件顺序

确保认证中间件在授权中间件之前执行,正确的中间件顺序如下:

app.UseHttpsRedirection();
app.UseAuthentication(); // 认证先于授权
app.UseAuthorization();
app.UseSwagger();
app.UseSwaggerUI(...);

内容的提问来源于stack exchange,提问作者rohan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 18:54:55