ORY Kratos v1.0.0对接Microsoft Azure OIDC遇PKCE及CORS错误求助
我自行部署了ORY Kratos v1.0.0,尝试对接Microsoft Azure(使用Microsoft登录)实现OIDC Connect功能。已在Azure B2C完成应用注册,配置了正确的重定向URL、客户端密钥,且PKCE显示绿色校验通过。
在kratos.yml的providers.config中配置如下:
- id: microsoft microsoft_tenant: common provider: microsoft client_id: xxxxxxxxxx client_secret: xxxxxxxxxxxxxx mapper_url: file:///etc/config/kratos/oidc.jsonnet scope: - email
但登录始终失败,Kratos返回错误信息:
"Unable to complete OpenID Connect flow because the OpenID Provider returned error "invalid_request": Proof Key for Code Exchange is required for cross-origin authorization code redemption."
(我的Google和GitHub OIDC配置均可正常工作。)
我的Kratos服务器部署在auth.mydomain.com,登录页面部署在accounts.mydomain.com。请问可能是什么问题导致的?
问题原因及解决方案
1. 核心原因
你的Kratos服务与登录页面分属不同子域名,属于跨域授权码兑换场景,Azure对此强制要求使用PKCE流程。尽管Azure后台显示PKCE校验通过,但Kratos针对Microsoft OIDC的默认配置未显式启用PKCE,导致不符合Azure的强制要求。
2. 解决步骤
- 显式启用PKCE配置:在Kratos的Microsoft OIDC提供商配置中添加PKCE相关字段,强制开启PKCE模式:
若需要更精细配置,可指定Azure要求的- id: microsoft microsoft_tenant: common provider: microsoft client_id: xxxxxxxxxx client_secret: xxxxxxxxxxxxxx mapper_url: file:///etc/config/kratos/oidc.jsonnet scope: - email pkce: true # 新增此配置项S256哈希方法:pkce: enabled: true method: S256 - 验证跨域配置一致性:确认Azure应用注册中的重定向URL指向Kratos的回调地址(例如
https://auth.mydomain.com/self-service/methods/oidc/callback/microsoft),同时Kratos配置中的self_service.flows.login.ui_url需正确指向accounts.mydomain.com的登录页面,确保跨域跳转链路正常。
3. 为何Google/GitHub可正常工作?
Google与GitHub的OIDC实现对跨域场景的PKCE要求相对宽松,且Kratos针对这两个提供商的默认配置已自动适配PKCE流程,因此无需额外配置即可正常运行。
内容的提问来源于stack exchange,提问作者markop

