You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Android应用接入Duende IdentityServer登录失败问题求助

问题根源及解决方法

核心问题分析

你的问题本质是授权流程入口错误,加上客户端与Android端的端点配置不匹配,导致登录页面无法获取授权上下文(即returnUrl),最终无法完成回调。

具体错误点与修复步骤

1. 修正Duende IdentityServer客户端配置(appsettings.json)

当前AndroidID客户端存在两处关键配置错误,需调整:

"Clients": {
  "AppName": {
    "Profile": "IdentityServerSPA",
  },
  "AndroidID": {
    "Profile": "IdentityServerSPA",
    "Enabled": true,
    "ClientId": "AndroidID",
    "RequireClientSecret": false,
    "ClientName": "AndroidApp",
    "ClientSecrets": [ { "Value": "" } ],
    "RequirePkce": true,
    "AllowedGrantTypes": [ "code" ], // 移除不需要的client_credentials、implicit,仅保留授权码流程
    "AllowedScopes": [ "openid", "profile", "email", "phone", "SIGADAPI" ], // 与Android端scope保持一致,替换原错误的"api"
    "RedirectUris": [ "https://aaa/authentication/login-callback" ], // 替换为Android端实际使用的回调地址
    "RequireConsent": false,
    "AllowOfflineAccess": true,
    "PostLogoutRedirectUris": [ "https://aaa/connect/endsession" ] // 补充登出回调地址
  }
}

2. 修正Android端AppAuth配置

多个端点配置不符合IdentityServer标准,需调整:

{
  "client_id": "AndroidID",
  "redirect_uri": "https://aaa/authentication/login-callback",
  "end_session_redirect_uri": "https://aaa/connect/endsession",
  "authorization_scope": "openid email profile SIGADAPI",
  "authorization_endpoint_uri": "https://aaa/connect/authorize", // 替换为IdentityServer授权端点,而非直接登录页面
  "token_endpoint_uri": "https://aaa/connect/token",
  "registration_endpoint_uri": "",
  "user_info_endpoint_uri": "https://aaa/connect/userinfo", // 替换为标准用户信息端点
  "https_required": true,
  "end_session_endpoint": "https://aaa/connect/endsession",
  "client_secret" : "",
  "response_types": "code",
  "jwks_uri": "https://aaa/.well-known/openid-configuration/jwks",
  "revocation_endpoint": "https://aaa/connect/revocation",
  "grant_types": [ "code" ], // 仅保留授权码流程
  "scopes_supported" :  [ "openid", "profile", "email", "phone", "SIGADAPI" ]
}

3. 确保登录页面正确处理授权上下文

登录页面(Login.cshtml)的returnUrl需由IdentityServer的/connect/authorize端点跳转携带,而非直接访问登录页面。确认:

  • 客户端发起授权请求时,目标是/connect/authorize而非直接登录页面,此时returnUrl会自动包含授权上下文
  • 登录逻辑中,调用_signInManager.PasswordSignInAsync成功后,必须执行return Redirect(returnUrl)跳转,不能忽略该参数

验证流程

  1. 重启IdentityServer服务,确保配置生效
  2. Android端发起授权请求,此时会先进入/connect/authorize端点,再引导至登录页面,returnUrl将正常携带授权上下文
  3. 登录成功后,系统会自动回调至Android端配置的redirect_uri,完成令牌获取流程

内容的提问来源于stack exchange,提问作者Andrei Dobrin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 02:55:34