NextJS+NextAuth对接IdentityServer4未调用/connect/token问题
你遇到的核心问题是NextAuth没有触发code换token的后端流程,这大概率是回调路由配置错误导致的,以下是具体排查和修复步骤:
1. 修正OAuth回调地址配置
NextAuth的OAuth流程依赖内置的后端回调端点,而非你自定义的/callback页面。你当前设置的redirect_uri指向了前端页面,导致NextAuth无法捕获到code并触发/connect/token请求。
需要将redirect_uri修改为NextAuth的标准回调路径:
http://localhost:3000/api/auth/callback/custom-provider
(其中custom-provider是你定义的provider id)
2. 更新IdentityServer4客户端配置
在IdentityServer4的客户端设置中,必须将上述新的回调地址添加到AllowedRedirectUris列表里。之前的create-react-app用的是不同的回调地址,这个新地址必须单独配置,否则IdentityServer会拒绝回调请求。
同时确保客户端的AllowedGrantTypes包含authorization_code,AllowedScopes包含你请求的setcompany.api、openid、profile。
3. 移除不必要的自定义参数
你在authorization.params里添加的site不是OAuth/OIDC的标准参数,可能干扰NextAuth的流程解析。如果业务需要传递这个参数,建议通过state参数携带,或者在IdentityServer端做自定义处理,不要直接放在授权请求参数里。
4. 改用OIDC类型的Provider
IdentityServer4是标准的OIDC实现,建议将provider的type从oauth改为oidc,NextAuth的OIDC Provider会更适配这类服务的流程,自动处理well-known配置和token请求逻辑。
修改后的配置示例
export const authOptions = { providers: [ { id: "custom-provider", name: "custom-provider", type: "oidc", clientId: "nc-setcompany", checks: ["pkce", "state"], wellKnown: "https://localhost:44392/.well-known/openid-configuration", authorization: { params: { scope: "setcompany.api openid profile", redirect_uri: "http://localhost:3000/api/auth/callback/custom-provider", response_mode: "query", response_type: "code", }, }, }, ], session: { strategy: "jwt", }, };
关于自定义callback页面的说明
不需要在callback/page.tsx里手动发起token请求。NextAuth的/api/auth/callback/custom-provider端点会自动完成code交换token、用户信息获取等流程,完成后会自动跳转到你配置的callbackUrl(默认是首页)。你自定义的callback/page.tsx可以作为登录成功后的跳转目标,但不需要处理OAuth逻辑。
内容的提问来源于stack exchange,提问作者auron344

