You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ORY Kratos v1.0.0对接Microsoft Azure OIDC遇PKCE及CORS错误求助

ORY Kratos v1.0.0 对接Azure OIDC登录失败问题

我自行部署了ORY Kratos v1.0.0,尝试对接Microsoft Azure(使用Microsoft登录)实现OIDC Connect功能。已在Azure B2C完成应用注册,配置了正确的重定向URL、客户端密钥,且PKCE显示绿色校验通过。

在kratos.yml的providers.config中配置如下:

- id: microsoft
        microsoft_tenant: common
        provider: microsoft
        client_id: xxxxxxxxxx
        client_secret: xxxxxxxxxxxxxx
        mapper_url: file:///etc/config/kratos/oidc.jsonnet
        scope:
          - email

但登录始终失败,Kratos返回错误信息:

"Unable to complete OpenID Connect flow because the OpenID Provider returned error "invalid_request": Proof Key for Code Exchange is required for cross-origin authorization code redemption."

(我的Google和GitHub OIDC配置均可正常工作。)

我的Kratos服务器部署在auth.mydomain.com,登录页面部署在accounts.mydomain.com。请问可能是什么问题导致的?


问题原因及解决方案

1. 核心原因

你的Kratos服务与登录页面分属不同子域名,属于跨域授权码兑换场景,Azure对此强制要求使用PKCE流程。尽管Azure后台显示PKCE校验通过,但Kratos针对Microsoft OIDC的默认配置未显式启用PKCE,导致不符合Azure的强制要求。

2. 解决步骤

  • 显式启用PKCE配置:在Kratos的Microsoft OIDC提供商配置中添加PKCE相关字段,强制开启PKCE模式:
    - id: microsoft
          microsoft_tenant: common
          provider: microsoft
          client_id: xxxxxxxxxx
          client_secret: xxxxxxxxxxxxxx
          mapper_url: file:///etc/config/kratos/oidc.jsonnet
          scope:
            - email
          pkce: true  # 新增此配置项
    
    若需要更精细配置,可指定Azure要求的S256哈希方法:
    pkce:
            enabled: true
            method: S256
    
  • 验证跨域配置一致性:确认Azure应用注册中的重定向URL指向Kratos的回调地址(例如https://auth.mydomain.com/self-service/methods/oidc/callback/microsoft),同时Kratos配置中的self_service.flows.login.ui_url需正确指向accounts.mydomain.com的登录页面,确保跨域跳转链路正常。

3. 为何Google/GitHub可正常工作?

Google与GitHub的OIDC实现对跨域场景的PKCE要求相对宽松,且Kratos针对这两个提供商的默认配置已自动适配PKCE流程,因此无需额外配置即可正常运行。


内容的提问来源于stack exchange,提问作者markop

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 14:39:56